About

Compliance software that knows where it is

NVector started with a specific problem: institutions in our region answer to several rulebooks at once, and the software that could handle that was priced for somebody else.

The gap we found

A regulated institution in this region is rarely working to one standard. A bank holds ISO 27001 and answers to SAMA. A supplier to the energy sector carries NCA ECC and an Aramco certification on top. A healthcare group runs HIPAA alongside an information security standard. The same control gets implemented once and then written up three times, in three different formats, for three different audiences.

The international GRC suites that could have helped cost between two hundred thousand and two million US dollars a year, took twelve to twenty-four months to configure, and shipped with little knowledge of regional regulation. So the work was being done in spreadsheets, email threads and folders of PDFs — by teams who knew that would not survive an examination.

What we built instead

NVector ships with the regulatory content already loaded. Turn on a framework and its full requirement set is there, mapped to a library of plain-language controls that spans governance, access, data protection and resilience. There is no six-month content project, because the content is the product.

Eight frameworks ship with the product today: NIST CSF and ISO/IEC 27001 as the international baselines, NCA ECC and SAMA CSF for the Gulf, SOC 2 and CIS Controls for assurance and prioritisation, HIPAA for healthcare, and Aramco CCC for the energy supply chain. Work a control once and it closes the requirement it satisfies in every one of them you have switched on.

What we believe

  • Regional content is the product. Generic frameworks with a customisation project attached are not compliance software.
  • Work should count once. If a control satisfies eight requirements, the system should say so — not make you file it eight times.
  • Priced to be reachable. A microfinance bank has the same regulatory obligations as a large one and a fraction of the budget. Hence a free tier that is genuinely free.
  • Your data stays where your policy says. Cloud, on-premise and air-gapped are all first-class options, not enterprise upsells.
  • Evidence beats assertion. Every claim in the platform is backed by a document, a sign-off and an entry in an audit trail nobody can edit.

Who NVector is for

The platform is built for organisations that are examined, not just audited.

Banks & DFIs

Commercial banks, microfinance banks and development finance institutions under central bank supervision.

Insurers & NBFIs

Non-bank financial institutions carrying cyber and operational resilience obligations.

Healthcare

Hospital groups working to HIPAA alongside information security standards.

Critical infrastructure

Energy, telecom and government-linked entities with data residency and air-gap requirements.

Talk to the people building it

No SDR script and no discovery call before the demo. You will speak to someone who knows the frameworks.