Trust Center
How trust is built before it's asked for
This page is for governance, compliance, and procurement teams: who PAS is, and how governance is built into our systems rather than living in a document outside them.
Who is PAS?
Parashot Al Amanah for Artificial Intelligence Consultations and Solutions (W.L.L.), registered in the State of Qatar under Commercial Registration No. 249184, with an approved commercial activity of Artificial Intelligence consultancy and solutions. Based in Doha, Qatar.
How we handle data
The website itself does not store visitor data in a database; the contact form is delivered by email only. For an actual project, the data architecture, storage scope and location are defined within that specific project's scope, by agreement with the institution.
How governance is built into systems
- Role-based access control (RBAC) — each user sees and executes only what their role permits.
- Segregation of duties — no single person holds every step of a process.
- Maker/Checker on sensitive decisions before execution.
- An audit trail for every action: who performed it, when, and under which rule.
- A documented exception path instead of an unrecorded workaround.
- Mandatory human oversight on decisions that require it — technology supports, humans decide.
AI governance
AI inside PAS solutions operates within a defined, governed scope, and does not on its own make compliance, legal, customer-restriction, or final financial decisions. Full detail on the Responsible AI page.
Deployment options
The appropriate deployment environment — the institution's own environment, a private cloud, or on-premise where technically supported — is agreed within each project's scope, according to the institution's regulatory and security requirements.
Integration architecture
Integration with an institution's systems (such as core banking, payment gateways, or government case-management systems) is designed around that institution's actual available APIs — never claiming an integration that does not exist.
Data minimization, secrets, and logging
- We collect only the minimum data necessary for the stated purpose.
- No secrets or access keys appear in client-side code, the browser bundle, or the source repository.
- System logs do not contain sensitive personal data or the full content of a request.
Procurement readiness
On formal request, PAS can provide: a company profile, commercial registration, technical proposal, solution architecture, security questionnaire, NDA, data protection requirements, deployment options, integration architecture, project governance model, and support model. Sensitive documents are not published publicly without need.