Emtithal+
A Saudi compliance intelligence (GRC) SaaS that uses AI to scan contracts for PDPL violations, monitor regulations, and keep a cryptographically tamper-evident audit trail — built end-to-end with Lovable, Next.js, and Supabase.

01. Client Goal
Build a production-grade GRC (compliance) SaaS for the Saudi market that detects regulatory violations in documents using AI, monitors regulatory changes with business impact analysis, keeps a provably tamper-evident audit trail, supports multi-tenant organizations with a full admin dashboard, and is enterprise-ready: secure, fast, and bilingual (English/Arabic).
02. Client Challenge
03. The Turning Point
“Core principle: "AI recommends · Humans attest · Rules enforce · Audit proves." AI is always a suggestion, never a decision-maker. The product is structured in three layers — AI analysis (OCR, RAG, findings), governance (assessments, regulatory intelligence), and assurance (hash-chained audit).”
04. The Process
AI Compliance Analysis
Scans contracts for PDPL violations with citation-grounded findings and remediation suggestions.
Regulatory Intelligence
Maps regulatory changes to affected documents, departments, and financial exposure; auto-assigns follow-up tasks.
NCA Framework Detection
Detects and assesses ECC/TCC/DCC frameworks from uploaded documents, with XLSX catalogue importer and validation scripts.
Tamper-Evident Audit Trail
Hash-chained entries, advisory locks, a single canonical write path, and CI verification so the audit log is provably intact.
Multi-Tenant Admin
Organizations, users, subscription plans, audit log, analytics, and system health — protected server-side.
Security & Auth
Supabase RLS on every table, HIBP breach checks, email verification, and secrets that never reach the browser.
Arabic RTL & Design System
Full Arabic support with a Saudi Sovereign design system for enterprise trust and readability.
Quality & Testing
Vitest unit tests, Playwright E2E, framework benchmarks, and k6 load testing for production confidence.