Built for the United Arab Emirates

Client communication and customer data that never leave the UAE

On 24 April 2026 the Central Bank of the UAE told licensed financial institutions to stop using WhatsApp, Telegram and similar consumer apps for client business. We build the replacement: a branded, encrypted, fully auditable communication platform hosted inside the UAE — plus the data systems and custom software behind it.

100%
Customer data stored on UAE-resident infrastructure
6–10 wks
Typical migration off instant messaging for one business line
AES-256
Encryption at rest with keys held under UAE control

The compliance window has already closed

Institutions were given until 30 April 2026 to stop new interactions over instant messaging platforms. The CBUAE confirmed that using a VPN does not exempt an institution, and warned that non-compliance may lead to supervisory action or financial penalties. Separately, the Consumer Protection Standards have long required all consumer and transaction data to be held and stored inside the UAE. See the full regulatory timeline.

What we do

Four services, one principle: the data stays here

We are software engineers, not a compliance consultancy. Our job is to build and migrate the systems that make residency real — and to leave you with evidence a supervisor will accept.

Compliant Client Communication Platform

A branded, UAE-hosted replacement for WhatsApp and Telegram in client-facing conversations — end-to-end encrypted, fully auditable, with every message and attachment stored on infrastructure inside the Emirates.

Explore

Data Residency & Data Management

We map where your customer data actually lives, migrate what sits offshore into UAE data centres, and leave behind a governed system with classification, retention, access control and evidence you can hand a supervisor.

Explore

Custom Software, SaaS & Mobile Apps

Bespoke platforms built residency-first: portals, ERPs, internal tools, customer apps and full SaaS products, architected so that regulated data never leaves the country by accident.

Explore

Web Development & Digital Presence

Fast, accessible, search-optimised websites and web applications for UAE businesses — engineered for Core Web Vitals, Arabic and English, and hosting that keeps form submissions in the country.

Explore

The gap

Why consumer messaging cannot be made compliant

The problem is not encryption — WhatsApp has that. The problem is that a regulated institution cannot control where the data sits, cannot produce a complete record, and cannot prove who said what to whom.

Regulatory requirements mapped against consumer messaging apps and a purpose-built channel.
Requirement Consumer messaging apps Frag & Frame platform
Customer data stored inside the UAE Servers and backups offshore UAE data centres, in-country backups
Complete, exportable audit trail Held on personal devices, deletable Immutable server-side record
Institutional control of encryption keys Controlled by the app vendor Keys managed under UAE control
Verified identity on both sides Phone number only — trivially spoofed Authenticated client and staff sessions
Retention, deletion and legal hold Not enforceable by the institution Policy-driven, centrally enforced
Staff conduct monitoring Off-channel contact is invisible Every interaction attributable
Data retrieved or destroyed on exit No contractual mechanism Contractual and technical guarantee

Requirements summarised from the CBUAE Consumer Protection Standards and the CBUAE notice of 24 April 2026. This comparison is a general engineering assessment, not legal advice.

Who we work with

Regulated and data-sensitive businesses across the Emirates

Direct CBUAE licensees feel this first. But anyone holding UAE customer data faces the same question about where that data actually lives.

Banks & Finance Companies

Licensed banks, finance companies and exchange houses under direct CBUAE supervision.

Insurance & Brokerage

Insurers and brokers handling policyholder data and claims correspondence.

Payments & Fintech

Stored-value facilities, payment providers and retail payment services licensees.

Real Estate & Mortgage

Developers, brokerages and mortgage intermediaries handling KYC and financial records.

Healthcare

Providers subject to UAE health data residency rules alongside the federal PDPL.

Legal & Professional Services

Firms holding privileged client information and regulated correspondence.

How an engagement runs

From channel inventory to signed-off evidence

We start by finding out what is actually happening — which is rarely what the policy document says. Then we build, migrate and hand over something your compliance function can stand behind.

  1. Discovery and data mapping

    We inventory every client-facing channel in use, including the unofficial ones, and map where consumer and transaction data is stored, cached, backed up and logged.

  2. Residency architecture

    We design the target state: UAE hosting, key management, retention, access control and integration points with your core systems — reviewed with your risk function before build.

  3. Build and deploy

    The platform is deployed on UAE infrastructure under your brand, integrated with your CRM and core systems, and hardened with penetration testing before a single client touches it.

  4. Migration

    Staff are trained, clients are moved across business line by business line with a clear notification, and legacy messaging channels are closed down rather than quietly left open.

  5. Evidence handover

    You receive architecture and data-flow documentation, a control register, audit export procedures and runbooks — the pack you hand to a supervisor or an external auditor.

Questions

Frequently asked questions

Did the UAE Central Bank actually ban WhatsApp for banks?

The CBUAE issued a notice on 24 April 2026 instructing licensed financial institutions to stop using WhatsApp, Telegram and similar consumer messaging platforms to deliver financial services or handle customer information, with compliance expected by 30 April 2026. It is a prohibition on the regulated use of those channels — sending statements, confirming transactions, transmitting OTPs or PINs, and exchanging documents containing personal or financial data. The CBUAE also confirmed that using a VPN does not exempt an institution.

Where does the requirement to store customer data in the UAE come from?

It predates 2026. The CBUAE Consumer Protection Regulation and the accompanying Consumer Protection Standards require licensed financial institutions to hold and store all consumer and transaction data within the UAE. The 2026 activity — the messaging prohibition and the sovereign financial cloud launched with Core42 in February 2026 — represents enforcement and infrastructure catching up with a rule that was already on the books.

We are not a bank. Does any of this apply to us?

The CBUAE messaging notice binds licensed financial institutions. But the federal Personal Data Protection Law (Federal Decree-Law No. 45 of 2021) restricts cross-border transfer of personal data for everyone, and the UAE Data Office has not published an adequacy list. Healthcare has its own residency rules. In practice, most UAE businesses holding customer data are better served by in-country processing regardless of licence type.

What can replace WhatsApp for talking to clients?

The CBUAE pointed institutions towards mobile banking apps, online portals, recorded call centres and branches. Our platform gives you a branded messaging channel with the same immediacy clients expect from WhatsApp — text, files, voice and video — but end-to-end encrypted, stored on UAE infrastructure, and producing a complete audit record.

How long does a migration off instant messaging take?

A focused deployment for a single business line typically runs six to ten weeks: channel inventory and data mapping, platform deployment on UAE infrastructure, integration with your core systems, staff and client migration, then evidence handover. Larger multi-entity programmes are phased by business line so client contact is never interrupted.

Where exactly is the data hosted?

Inside the UAE. We deploy to UAE regions of major cloud providers, to local licensed data centres, or on-premise within your own environment — whichever your risk function prefers. Encryption keys stay under UAE control, and backups, logs and disaster-recovery copies are held in-country alongside production data.

Can you work with our existing core banking or CRM system?

Yes. The communication platform is designed to sit alongside existing systems and integrate through APIs — pushing conversation records into your CRM, pulling client identity from your core system, and feeding your archive or e-discovery tooling rather than becoming another silo.

Do you provide legal advice on compliance?

No. We are software engineers, not a law firm. We build and migrate systems so they align with published regulatory requirements, and we produce the technical evidence your compliance and legal teams need. Interpretation of your specific obligations should come from qualified UAE counsel.

Find out where your customer data actually lives

A short discovery call and a review of your current channels and hosting. No obligation, and you keep the findings whether or not you work with us.