Architecture العربية

ADR-0001 — Hosting Platform & Data Residency

Status: Proposed · Date: 2026-07-20 · Deciders: Amir Haroun (Tech Lead), Qwizin Management Supersedes: — · Related: ADR-0003 (orchestration), ADR-0005 (video), RISK-01


Context#

Qwizin must be hosted somewhere that satisfies CON-13 (KSA data residency), supports Kubernetes (CON-15), and respects CON-01 (budget sensitivity). The platform stores commercial registrations, VAT cards, employee PII, assessment records, and potentially recorded consultations.

The architect's initial framing treated in-Kingdom residency as a legal mandate. Research materially revised that premise, and the revision is recorded here because it changes why the decision is made, even though it does not change what is decided.


⚠ Finding that revises the premise: PDPL does not mandate in-Kingdom storage for private-sector data#

This is the most commonly misreported fact in the Saudi cloud market, and the source documents implicitly assume the stricter reading.

What the law appears to actually say:

  • PDPL (Royal Decree M/19, 2021, amended 2023) Article 29 permits cross-border transfer subject to conditions: a permitted purpose, no prejudice to national security, an adequate protection level in the destination or an approved safeguard, and data minimisation.
  • The Regulation on Personal Data Transfer Outside the Kingdom (SDAIA, September 2024) provides the mechanisms: Saudi Standard Contractual Clauses, Binding Common Rules (intra-group only), or a Certificate of Accreditation — plus a mandatory pre-transfer risk assessment (Art. 7).
  • Specialist counsel commentary states directly that the perception of Saudi Arabia as a data-localisation jurisdiction is inaccurate for private-sector personal data.

Where the stricter reading is correct: once the platform processes Saudi Government Data, the CST regime (Cloud Computing Services Provisioning Regulations, Decision 506/1445, 2023) applies, and government data may not leave the Kingdom in any form, permanently or temporarily. Given SRC-DECK's municipality/SFDA ambition, this is a live future constraint.

⚠️ Conflicting sources — deliberately surfaced. A US trade-advisory source states that companies must store personally identifiable data within Saudi Arabia absent exemption. That framing is inconsistent with the statutory text as read by specialist law firms. This report is not a legal opinion. A written KSA data-protection opinion should be obtained before relying on either reading. See RISK-03.

Practical consequence: in-Kingdom hosting is not legally forced today, but it eliminates the entire cross-border transfer compliance workstream — the SCCs, the per-transfer risk assessments, the ongoing evidencing — and it pre-satisfies the CST government-data rule. That is the real justification, and it is a strong one.

Enforcement is live#

SDAIA committees have reportedly issued 48 violation decisions across 2025–2026. Penalties: up to SAR 3,000,000 and/or 2 years' imprisonment for intentional disclosure of sensitive data (Art. 35), and administrative fines up to SAR 5,000,000 per violation (Art. 36). (The "48 decisions" figure is sourced to consultancies, not an SDAIA publication — treat as an enforcement-intensity signal, not a precise fact.)


Options Considered#

Provider KSA region GA? Managed K8s Verdict
Oracle OCI Jeddah me-jeddah-1 (2020), Riyadh me-riyadh-1 (2024) Two GA regions OKE ✅ Recommended
Google Cloud Dammam me-central2, 3 AZs (2023) ✅ GA GKE ✅ Strong second
SCCC / Alibaba (stc JV) Riyadh, 2 AZs ✅ GA ACK ⚠️ ticket-gated, no Serverless Viable, weaker
Microsoft Azure "Saudi Arabia East" Q4 2026 Unpublished Disqualified — unavailable
AWS Riyadh (claimed) Not verifiable Disqualified — AWS's own docs list no KSA region
Local (Mobily, NourNet, Sahara, Center3) Various None found Disqualified — no managed K8s

Notable disqualifications#

  • AWS. Marketing and SEO sources claim a January 2026 GA for me-central-2. AWS's own regions documentation lists only Bahrain and UAE in the Middle East. Absent an AWS-owned announcement, AWS KSA is treated as unavailable. This directly contradicts a common assumption and should be re-checked before any final commitment.
  • Azure. Genuinely capable, genuinely unavailable until Q4 2026, with no published service-rollout schedule — so AKS at launch is not guaranteed. A reasonable future migration target, not a founding decision.

Decision#

Primary: Oracle Cloud Infrastructure, Riyadh (me-riyadh-1), with Jeddah (me-jeddah-1) as the disaster-recovery region.

Rationale#

  1. Only provider offering in-country DR. Two GA in-Kingdom regions means a real disaster-recovery posture without a single byte leaving KSA. Every other provider offers one region at best, forcing DR to be either cross-border (reintroducing the transfer workstream) or same-region multi-AZ (which does not protect against regional loss). This satisfies CON-13 and pre-satisfies the CST government-data rule for the SRC-DECK municipality/SFDA ambition.
  2. Cost structure is the decisive differentiator under CON-01. Oracle prices services uniformly across all regions globally — KSA costs the same as North America. Google Cloud Dammam, by contrast, ranks as the most expensive GCP region measured (#42 of 42, ~+88.5% above the cheapest). Over a multi-year SaaS run against an explicitly budget-sensitive constraint, this dominates every other cost factor. OCI egress pricing is also the cheapest among the majors — directly relevant given video egress is the dominant variable cost (ADR-0005).
  3. OKE is competent and unremarkable — which is what is wanted. Standard upstream Kubernetes, standard tooling. The purchase here is residency plus a managed control plane, not a differentiated Kubernetes.
  4. Cleanest GCC expansion path (CON-12). Same catalogue, same prices, same IaC across KSA and UAE.
  5. Direct commercial relationship — no mandatory reseller in the support path.

Google Cloud Dammam is the second choice, and there is one scenario where it should win#

Choose Google instead if government contracts become a strategic priority rather than a possibility. Google is the one provider with a published CST Class C licence plus a purpose-built sovereignty package — Sovereign Controls by CNTXT, including External Key Management and Key Access Justifications (a cryptographic veto over cloud-provider key access). That is a genuinely differentiated control that performs well in government procurement review.

Accept in exchange: the highest cost of any option; a single in-Kingdom region (no in-country DR); and total dependence on CNTXT — Google Cloud customers with a KSA billing address must purchase all Google Cloud through CNTXT and cannot buy Google Customer Care directly. That is a single-intermediary dependency for both billing and support across the entire estate.


Consequences#

Positive#

  • Cross-border transfer compliance workstream eliminated entirely
  • In-country DR achievable — unique to Oracle among viable options
  • Cost structure aligns with CON-01; no regional premium
  • Government-data path (CST) pre-satisfied at the infrastructure layer
  • GCC expansion is a region addition, not a re-platform

Negative / Accepted trade-offs#

  • Smaller ecosystem than AWS/GCP. Fewer third-party integrations, fewer engineers with OCI experience, thinner community troubleshooting material. Mitigated by the fact that the workload is standard Kubernetes plus PostgreSQL plus object storage — deliberately unexotic, and portable by construction.
  • OKE is less mature than GKE. Accepted; the architecture uses no GKE-specific capability.
  • Vendor concentration. Mitigated by keeping the deployment portable (see below).

Portability requirement generated by this decision#

Because the provider landscape in KSA is in flux — Azure arriving Q4 2026, AWS status unresolved — the deployment must not become Oracle-specific:

  • Vanilla upstream Kubernetes primitives; no proprietary control-plane features
  • PostgreSQL, Redis, and S3-compatible object storage — all standard interfaces
  • Infrastructure as code with provider-specific detail isolated in modules
  • No dependency on a proprietary queue, function runtime, or serverless container product

This is a deliberate constraint that trades some managed-service convenience for the ability to move. Given the market volatility, that trade is correct.


⚠ Verification Gaps — must be closed before commitment#

Recorded honestly rather than papered over. This decision is provisional on items 1–4.

# Gap Why it matters
1 Per-region service matrix for me-riyadh-1 not verified. Oracle's service-availability page returned HTTP 403. Managed Redis (OCI Cache), Streaming, Vault, and container registry availability in-region are assumed, not confirmed. A missing managed Redis or registry changes the architecture
2 No verified 2026 KSA per-SKU pricing obtained. The cost argument rests on Oracle's published pricing-uniformity claim, which is structurally verified but not numerically confirmed for KSA. Cost is the primary argument for Oracle
3 Oracle's CST registration class is unverified. Google's and Huawei's Class C status is documented; Oracle's is not. Gates all government/municipality/SFDA work — could invert this decision
4 PDPL localisation reading is contested (see above). Central legal premise
5 AWS KSA GA status unresolvable from AWS-owned sources Would reshuffle the ranking if a KSA region exists
6 NCA Cloud Cybersecurity Controls text could not be retrieved Binding control set for regulated/government workloads

Required actions before ratifying#

  1. Pull the live region-availability matrix from the OCI console — not marketing pages — for Riyadh and Jeddah
  2. Obtain written quotes from Oracle and (for comparison) CNTXT for the target footprint
  3. Confirm Oracle's CST registration class in writing
  4. Commission a KSA data-protection legal opinion covering PDPL Art. 29 and the CST government-data path

Notes#

The research underpinning this ADR hit the session's web-search budget before all items could be verified. The gaps above are stated rather than filled from memory. Cost and regulatory status are precisely the areas where a plausible-sounding wrong number causes real damage, so no figure appears here that was not retrieved or explicitly labelled as structural inference.

Tech Lead · Amir Haroun Draft v0.1 · research & design only