Skip to main content
Security & Deployment

Your data perimeter. Your rules.

For government and regulated organisations, the first question in any data governance project is where the metadata lives. Goava gives you a clear answer: fully inside your own data centre, or in cloud hosted within Saudi Arabia — with enterprise authentication and an audit-friendly activity history.

Enterprise security, ready for procurement review

The controls your security and compliance teams will ask about — answered before they ask.

Role-based access control

Fine-grained roles and policies define who can view, edit, and own every metadata asset — from a single table to an entire domain.

Single sign-on

Connect your existing identity provider through OIDC, SAML 2.0, or LDAP. Access follows the identities and groups you already manage.

JWT API authentication

Service-to-service and automation access is secured with JWT tokens, so pipelines and integrations authenticate as strictly as people do.

Audit-friendly activity history

Every change to classifications, ownership, glossary terms, and descriptions is recorded in activity feeds — who changed what, and when.

Self-hosted on-premises

Run the full platform inside your own data centre, within your network perimeter and under your operational control.

Cloud inside the Kingdom

Prefer managed hosting? Deploy on cloud infrastructure located inside Saudi Arabia, keeping metadata residency within national borders.

Deployment options

Metadata residency by design

For government entities, where metadata lives is the first procurement question — and it deserves a plain answer. Goava deploys fully on-premises inside your perimeter, or in cloud hosted inside Saudi Arabia. In both models, the platform catalogs metadata about your systems; your underlying data stays in the source systems where it already lives.

  • Fully on-premises: the entire platform runs inside your own data centre
  • In-Kingdom cloud: managed hosting on infrastructure located in Saudi Arabia
  • Metadata-only by design: source data is never moved into the catalog
  • Same platform, same features, in both deployment models
Discuss your deployment
orders · data-team · PII
customers · analytics · Certified
revenue_daily · finance

Arabic-native operations

Your stewards work in Arabic

Goava ships with a native bilingual interface — Arabic with the ar-SA locale, and English — so your Data Management Office never has to choose between usability and adoption. Stewards can document, classify, and review in formal Arabic while technical teams work in English, on the same catalog.

  • Full Arabic interface built on the native ar-SA locale
  • Business glossary terms maintained in Arabic and English
  • Stewards classify, describe, and approve in the language they work in
  • Each user chooses their own language — one catalog, two languages
Explore governance features
مصطلح: حوكمة البيانات
Data Steward · مسؤول البيانات
Lineage · سلسلة النسب

Security and deployment questions

Where is our data stored?

Goava stores metadata — descriptions, classifications, lineage, and data quality results — wherever you deploy the platform: in your own data centre, or in cloud hosted inside Saudi Arabia. Your underlying data remains in your source systems; the catalog never becomes a copy of it.

What does the platform actually access?

Goava connects to your systems to read metadata: schemas, table and column names, descriptions, dashboard and pipeline definitions, and API specifications. Optional profiling computes statistics such as row counts, null percentages, and freshness — the results are stored as metadata, and your records are not copied into the catalog.

Which SSO providers can we use?

Any identity provider that supports OIDC, SAML 2.0, or LDAP. Roles and groups from your provider map to Goava's role-based access control, and JWT tokens secure service and API access.

How do updates work for on-premises deployments?

Updates ship as versioned releases that are applied inside your environment, on your change-management schedule. You stay in control of when and how the platform changes — nothing is forced from outside your perimeter.

Bring governance inside your perimeter

Talk to our team about on-premises and in-Kingdom cloud deployment, and what a rollout would look like in your environment.