Data Sovereignty
Data sovereignty and on-premises deployment
Vulnerability data describes where your weakest points are. In Cyprob that data sits in your own database, on your own servers, and stays there.
Why it matters
A vulnerability record is a precise description of what an attacker would need. Many institutions treat holding that record in a cloud account in another country as a risk in itself, and in regulated sectors the regulator often does not allow it either.
Cyprob handles this at the architecture level. The product runs on your own virtual machine and the database is your own PostgreSQL instance. No cloud account is opened, no telemetry is sent, and licence validation carries no data outside. The rules of the platform are set by your organisation, not by a vendor release calendar.

What it means for compliance
Once the location of the data is fixed, compliance questions are easier to answer. Saudi organisations keeping personal data inside the Kingdom under the Personal Data Protection Law can point to a database they operate themselves. The same applies to entities in the United Arab Emirates working under the federal data protection law, where the processing boundary is the institution's own network. The answer to the question of where the data lives is one sentence: on your server.
Common questions
Where exactly does the data live?
In your own PostgreSQL database, on your own servers. No cloud account is created, no telemetry leaves, no copy exists outside.
Does licence activation send anything out?
No. Activation works without an outbound connection on closed networks, so licensing does not undercut the sovereignty of the deployment.
What does this mean for data protection law?
Records that contain personal data are processed inside your own boundary. For regimes such as Saudi PDPL or the UAE federal data protection law, the answer to where the data sits is your own servers.