Search all 478 artefacts by title, document ID or content.
Printed on the standard letterhead. Page furniture, margins and repeating table headers come from the same stylesheet the PDF service uses.
Pensieve Labs
The operating system for hospitals
STM-AE-001
v1.0.0 | 01 August 2026
This document answers one question, asked in almost every UAE security review: which United Arab Emirates information security standards must our software vendor comply with, and is certification against any of them a condition of doing business?
Applies to DM-1, DM-2, DM-3 and DM-4. Where a standard's applicability turns on who operates the
infrastructure, that is noted in the row.
To state, standard by standard, whether it binds Edsol Edtech Pvt. Ltd. as the software supplier to a
private healthcare facility in the United Arab Emirates, whether certification is a gate, and, where it
is not, what Pensieve Labs offers instead.
No mandatory information security certification stands between
Edsol Edtech Pvt. Ltd.and a private hospital in Dubai.Not ISO/IEC 27001. Not SOC 2. Not the United Arab Emirates Information Assurance Standards. Not the Dubai Electronic Security Center's Information Security Regulation. The Abu Dhabi healthcare standard is a real requirement, but it is Abu Dhabi's and it does not reach a Dubai deal.
The two hard gates in this market are the health data localisation law and the health information exchange. They are
DIS-AE-008andDIS-AE-029. Neither is a security certification.
This is materially lighter than the security posture required in Pensieve Labs's European and
Australian markets, and it is one of the reasons this market is reachable. Pensieve Labs states it
plainly rather than allowing a buyer to assume a certification requirement that does not exist and then
disqualify a vendor that does not hold one.
| Standard | Who it binds | Does it bind Edsol Edtech Pvt. Ltd. as vendor to a private hospital? |
Is certification a gate? |
|---|---|---|---|
| United Arab Emirates Information Assurance Standards, current version v2.1, published by the national cyber security authority | Federal and local government entities, semi-government organisations, and critical infrastructure operators across the designated sectors, healthcare being one of them | No. Private sector organisations, including private hospitals, are encouraged to adopt voluntarily rather than mandated | No |
| Dubai Electronic Security Center Information Security Regulation, current version v3.1 | All Dubai Government entities and critical infrastructure in the Emirate. Mandatory for those in scope, requiring controls aligned with ISO/IEC 27001 and demonstration of implementation to the Center | No, not for a private hospital's vendor | No, for the private segment. Yes, if the customer is a Dubai Government health entity (Section 3) |
| Abu Dhabi Healthcare Information and Cyber Security Standard, version 2.0 | All Department of Health-licensed healthcare facilities, payers and service providers handling patient data in Abu Dhabi | Not in Dubai. Yes in Abu Dhabi: record system vendors are expected to demonstrate conformance before integration with the Abu Dhabi exchange | Not third-party certification. It is self-assessed and regulator-audited (Section 4) |
| Dubai Law No. 26 of 2015 on data dissemination and exchange | Government entities and designated data providers | No obligation on a private hospital's software vendor was identified [UNVERIFIED] |
No |
| ISO/IEC 27001, SOC 2, HITRUST | No United Arab Emirates instrument requires any of them of a private hospital's vendor | No | No |
The Dubai Electronic Security Center's regulation binds Dubai Government entities. The Emirate's own public healthcare provider organisation is a Dubai Government entity, and it operates the Emirate's public hospitals.
If
Pensieve Labsever targets those hospitals, the Information Security Regulation becomes a hard gate, the demonstration of implementation to the Center becomes a real programme measured in months rather than weeks, and the cost and time profile of the deal changes completely.
Pensieve Labs's position is that the Dubai Government health segment is out of scope. This is a
commercial decision recorded here so that it is not made accidentally in a sales meeting. Any approach from
that segment goes through the qualification gate at CHK-AE-001 Section 1 with the Information Security Regulation
scored as a blocking dependency, not as a questionnaire.
One deal-specific question remains open in the private segment. [UNVERIFIED] It was not established
whether any named private hospital in the Emirate carries a critical information infrastructure designation.
A facility that does would pull the national Information Assurance Standards, and possibly the Emirate's
Information Security Regulation, into scope for that deal. Ask the Customer's chief information security
officer directly at qualification. It is one question and it removes an expensive surprise.
The Abu Dhabi healthcare information and cyber security standard, version 2.0, replaced the earlier edition
and is a capability-based model with a three-tier control structure: Basic, Transitional and Advanced.
Record system vendors are expected to demonstrate conformance before integration with the Emirate's
health information exchange, and the named expectations include multi-factor authentication, encryption of
patient data, a zero-trust access architecture and United Arab Emirates data residency, the last of
which Pensieve Labs must satisfy in Dubai anyway.
Three facts make this the highest-value security artefact available in this market:
Status: Pensieve Labs has not produced an Abu Dhabi control mapping. It is on the market-entry list
at CHK-AE-001 Section 2 as gate U13, scoped as an Abu Dhabi prerequisite and a Dubai optional credential. It
is not represented as held, in progress or dated.
Pensieve Labs offers instead of a certificateEdsol Edtech Pvt. Ltd. holds no information security certification of any kind. WPR-GL-005 is the
assurance position and states it in the same terms. This document does not repeat it; it lists what a UAE
reviewer can actually be handed.
| Artefact | What it is | Tier |
|---|---|---|
WPR-GL-001 Security Whitepaper |
The complete control description: architecture, identity, encryption, logging, secure development, personnel, operations | Public |
ADD-GL-001 Security Addendum |
The contractual form of those controls, signed | Public |
QRE-GL-005 CAIQ self-assessment |
The cloud industry's own questionnaire, completed and published. Free, self-completed, and in a vocabulary a security reviewer already reads | Public |
CHK-GL-028 ISO/IEC 27001 Annex A mapping |
Control-by-control mapping. A mapping, not a certification, and labelled as one | Public |
CHK-GL-029 SOC 2 Trust Services Criteria mapping |
The same, for reviewers who work in that vocabulary | Public |
CHK-GL-030, CHK-GL-031, CHK-GL-032 |
CIS Controls v8, NIST Cybersecurity Framework 2.0 and OWASP ASVS mappings | Public |
| Independent penetration test summary | The single spend that answers more questionnaire questions than any other. Summary public, full report gated | Public / gated |
DIS-AE-008 |
The residency answer, which in this market is worth more than any certificate | Public |
QRE-GL-008, FRM-GL-125 |
Pre-written master answers, so the Customer's own questionnaire returns in days rather than weeks | Gated |
How to use these in a UAE security review. Send the mapping that matches the reviewer's own vocabulary,
not all of them. A reviewer working from an ISO/IEC 27001 checklist gets CHK-GL-028; a reviewer working
from a group cyber policy gets CHK-GL-030 or CHK-GL-031; a reviewer who sends a bespoke spreadsheet gets
QRE-GL-008 mapped onto it. Sending nine documents to answer one question reads as evasion.
A control mapping is not an audit. Pensieve Labs says this in the mapping documents themselves and
repeats it here because it is the point at which a vendor is most tempted to blur:
A mapping states which control
Pensieve Labshas implemented against each requirement of a framework. It isPensieve Labs's own assertion. No third party has verified it. It is not a certification, it does not confer one, andEdsol Edtech Pvt. Ltd.does not describe itself as "ISO 27001 aligned", "SOC 2 ready" or "compliant" with any framework it has not been assessed against.
The compensating evidence is the independent penetration test, the Customer's own right of audit under
DPA-AE-001 Section 8 and DPA-GL-001 clause 15, and the configuration verification right at DPA-AE-001 Section 2.6,
which, in this market, is a stronger assurance than a certificate, because it can be exercised at any time
and it tests the thing that actually matters.
7.1 Applicability determinations are drawn from secondary analysis. The applicability rows in Section 2 rest on
published commentary on the standards rather than on a determination by the issuing authority in respect of
Edsol Edtech Pvt. Ltd.. They are stated as Pensieve Labs's reasoned position and a Customer is
entitled to test them.
7.2 Critical information infrastructure designation is unresolved. Section 3. It is a deal-specific question and is asked at qualification rather than assumed either way.
7.3 No Abu Dhabi control mapping exists. Section 4.
7.4 Standards move. The version numbers in Section 2 are current as at 01 August 2026 and are
re-tested at each review. A superseded version number in a security review costs credibility out of
proportion to the error.
7.5 Nothing in this document is a statement about the Customer's own obligations. A Customer that is itself a government entity, a designated critical infrastructure operator or an Abu Dhabi-licensed facility has obligations this document does not describe.
| Question | Document |
|---|---|
| The overall assurance position and why no certification is held | WPR-GL-005 |
| What controls actually exist | WPR-GL-001, ADD-GL-001 |
| Framework mappings | CHK-GL-028 to CHK-GL-032, QRE-GL-005 |
| Where data resides: the answer that matters most in this market | DIS-AE-008 |
| Health information exchange requirements, including hosting | DIS-AE-029 |
| Audit and verification rights | DPA-AE-001 Section 2.6 and Section 8 |
| The gating table with owners and days | CHK-AE-001 Section 2 |
| Version | Date | Author | Summary |
|---|---|---|---|
| 1.0.0 | 01 August 2026 |
Pensieve Labs Security |
First issue. Applicability of the national information assurance standards, the Emirate's information security regulation, the Abu Dhabi healthcare standard and the Dubai data law determined for a private-hospital vendor. Dubai Government health segment recorded as out of scope with the reason. |
For and on behalf of
Edsol Edtech Pvt. Ltd.