Security & Controls
Safeguarding Client Funds and Data
Darb operates under the regulatory requirements and controls applicable in the Kingdom of Saudi Arabia. Client funds are held in segregated accounts with a licensed Saudi bank in accordance with applicable regulatory requirements. Darb does not use client funds for lending, investment, or its own expenditure.
Licensing and Regulatory Oversight
Darb is licensed by the Saudi Central Bank under license number 30/ش م/1447 and is subject to ongoing regulatory supervision and applicable requirements of the Saudi Central Bank.
Safeguarding of Client Funds
Client funds are held in segregated accounts with a licensed Saudi bank in accordance with applicable regulatory requirements. Client funds are maintained separately from Darb’s own funds and liabilities and are not used by Darb for lending, investment, or its own expenditure.
Data Hosting
Darb’s data is hosted within the Kingdom of Saudi Arabia in accordance with applicable data-hosting requirements. Data is not transferred outside the Kingdom.
Cybersecurity
Darb maintains technical and organizational controls designed to protect its systems and data and to comply with applicable cybersecurity requirements and Saudi Central Bank controls.
Transaction Controls
Darb applies multiple controls to card and account transactions to help prevent unauthorized activity and identify unusual transaction patterns.
Depending on the product and the controls configured by the client, these include:
- Spending limits
- Geographic restrictions
- Merchant and category restrictions
- Time-based restrictions
- Approval rules
- User authentication
- Real-time transaction monitoring
Transactions are evaluated against the applicable account and card controls and may be declined when they do not meet the configured requirements.
Permissions and Approvals
Darb enables clients to assign permissions to users according to their roles and responsibilities.
Governance controls include:
- Role-based user permissions
- Approval levels based on transaction value
- Multi-factor authentication for sensitive actions
- Logging of account access, changes, and administrative actions
- Audit trails for relevant activities and changes
Clients can review activity and changes associated with their accounts according to their assigned permissions.
Data Protection
Darb maintains technical and organizational measures designed to protect client data against unauthorized access, use, alteration, or disclosure.
Security measures include, as applicable to the relevant system and data:
- Encryption
- Access controls
- Multi-factor authentication
- Continuous system monitoring
- Activity and event logging
- Security incident response procedures
Compliance and Standards
Darb complies with the laws, regulations, and requirements applicable to its activities, including relevant requirements relating to:
- Personal Data Protection Law
- Saudi Central Bank requirements
- Applicable cybersecurity requirements
- Payment Card Industry Data Security Standard (PCI DSS)
- Applicable Visa membership requirements
Security Questions
Is Darb a bank?
No. Darb is a financial technology company licensed by the Saudi Central Bank to provide payment services within the scope of its license.
Where are client funds held?
Client funds are held in segregated accounts with a licensed Saudi bank in accordance with applicable regulatory requirements.
Does Darb use client funds?
Client funds are not used by Darb for lending, investment, or its own expenditure.
Where is client data hosted?
Darb’s data is hosted within the Kingdom of Saudi Arabia in accordance with applicable data-hosting requirements.
Who can access company data?
Access to systems and data is restricted to authorized personnel based on defined permissions and applicable security controls.
How are user permissions controlled?
Permissions can be assigned according to the user’s role, including access, transaction, approval, and administrative permissions. Sensitive actions are subject to additional authentication and control requirements.
Are actions and changes logged?
Yes. Relevant activities, actions, and changes are logged for audit, monitoring, and control purposes in accordance with applicable policies and procedures.