Security at RegX
Built for Sensitive UAE Workforce Data
RegX is designed to help organisations manage employee records, company documents, expiries, and compliance workflows with controlled access, clear accountability, and secure data handling.
Last updated: June 17, 2026
Our Security Principles
RegX is built around the following security principles. Security is built into the platform from the start — our goal is to help customers manage compliance information with controlled access, clear accountability, and strong protection of sensitive records.
Sensitive data should only be accessible to authorised users.
Customer workspaces must remain logically separated.
User permissions must be enforced on the server side, not only in the browser.
Important actions should be traceable through audit history.
AI-assisted processing should support human review, not replace accountability.
Documents should not be exposed through public links or uncontrolled access.
Workspace-Level Data Isolation
Each customer workspace in RegX is designed to keep its data separate from other workspaces.
Company records, employee profiles, uploaded documents, expiry records, compliance alerts, reports, and activity logs are associated with the relevant workspace. Users should only access information they are authorised to view within their assigned workspace.
RegX does not rely on browser-side workspace selection as a source of trust. Access to workspace data is verified through authenticated server-side checks.
Role-Based Access Control
RegX uses role-based access controls to help customers manage who can view, edit, upload, verify, or administer records.
Typical roles may include:
For service-centre or operational workflows, additional roles may be used, such as manager, receptionist, typist, reviewer, or other operational roles.
Permissions are designed to limit access based on the user's responsibilities. Customers should assign users only the access they need to perform their work.
Secure Authentication
RegX requires users to authenticate before accessing customer workspaces and sensitive records.
Authentication is designed to support secure sessions and controlled access to the platform. Account access should not be shared between users. Each user should have their own account so that activity can be tracked accurately.
Where supported, RegX may use additional security controls such as email verification, session controls, and future multi-factor authentication options.
Document Security
RegX is intended to manage sensitive documents such as passports, Emirates IDs, labour cards, visas, trade licences, establishment cards, and other company or employee records. Document security controls are designed around the following practices:
- Documents are linked to the correct company, employee, or workflow record.
- Documents should not be stored in public buckets.
- Document access should use controlled, time-limited access methods where applicable.
- Access to documents should be limited by workspace and user permissions.
- Document uploads, views, reviews, or changes may be recorded in activity history.
- Deleted or archived documents should follow the applicable retention and deletion rules.
Customers are responsible for ensuring that documents uploaded to RegX are accurate, lawful, and necessary for their compliance and operational purposes.
Audit History
RegX is designed to maintain an audit trail for important platform activity.
Depending on the enabled features, audit history may include:
Audit history helps customers understand who performed an action, when it happened, and which record was affected.
AI-Assisted Processing
RegX may use AI and OCR technologies to help extract information from uploaded documents, identify missing data, detect expiry dates, and highlight compliance risks.
AI is used as an assistant, not as a final authority.
Where AI-assisted processing is enabled, RegX aims to provide transparency around:
- The source document used
- The extracted field or value
- The confidence level, where available
- Whether the data has been reviewed by a human user
- The user and date of review
Customers should review important AI-extracted information before relying on it for operational or compliance decisions.
Example extraction review
- Passport expiry date
- 14 Aug 2027
- Source
- Passport copy
- AI confidence
- 94%
- Reviewed by
- Ahmed
- Reviewed on
- 12 Jan 2026
Encryption
RegX is designed to protect data in transit using secure HTTPS connections.
Where supported by the underlying infrastructure, data should be encrypted at rest using cloud-provider storage and database encryption controls.
Encryption is one part of the security model. RegX also relies on access controls, workspace isolation, audit history, secure application design, and operational controls to protect customer information.
Infrastructure and Hosting
RegX uses cloud infrastructure to deliver the platform.
Access to production systems should be restricted to authorised personnel only. Administrative access should follow the principle of least privilege, meaning team members only receive the access required for their role.
RegX may use trusted third-party infrastructure, storage, authentication, analytics, AI, OCR, email, and hosting providers to operate the service. These providers are used only where necessary to deliver and support the platform.
Backups and Availability
RegX is designed to support continuity of service through appropriate backup and recovery practices.
Backup frequency, retention periods, and recovery procedures may vary depending on the production environment, subscription plan, and operational requirements.
While RegX aims to provide a reliable service, no software platform can guarantee uninterrupted access at all times.
Customer Responsibilities
Security is shared between RegX and its customers. Customers are responsible for:
- Inviting only authorised users
- Assigning appropriate roles
- Removing users who no longer require access
- Keeping login credentials confidential
- Ensuring uploaded documents are lawful and accurate
- Reviewing AI-extracted information before relying on it
- Maintaining their own internal compliance procedures
- Not uploading information that is unnecessary for their use of the platform
Non-Government Affiliation
RegX is an independent compliance management platform. RegX is not a UAE government portal and is not affiliated with MOHRE, ICP, GDRFA, Dubai Economy, or any other UAE government authority unless expressly stated.
All official government transactions remain subject to the rules, systems, fees, approvals, and procedures of the relevant UAE authorities.
Reporting a Security Concern
If you believe you have discovered a security issue involving RegX, please contact us immediately.
Security contact
security@regx.aePlease include enough detail for us to understand and investigate the issue. Do not attempt to access, modify, download, or disclose data that does not belong to you.
Updates to This Page
We may update this Security page as RegX evolves, as new features are released, or as our security practices mature.
Last updated: June 17, 2026
