Opleca is an isolation-first identity platform hosted entirely inside Saudi Arabia. Enterprise sign-on, directory, and access management — on infrastructure your data is legally bound to, not merely promised to.
Every credential, session, log, and backup stays within Saudi regions. Residency isn't a checkbox on a foreign console — it's where the platform physically lives.
Fast, quiet, and legible. Directory, roles, and access read in seconds, not clicks — the admin surface an operator lives in eight hours a day, designed like it.
Tenant separation enforced in the database, not asserted in a slide. The boundary is a mechanism a security team can probe — and watch refuse.
Most multi-tenant platforms keep tenants apart with a WHERE clause someone has to remember. Opleca doesn't. Every tenant runs behind three independent layers — so a mistake at one layer is caught by the next, and a forgotten check reads zero rows instead of someone else's.
The data layer refuses a query with no tenant. The application can't construct a connection without a tenant identity. And a boundary assertion checks every response before it leaves the process.
It's the difference between “we're careful” and “the database won't let us be careless.”
OpenID Connect and SAML for your workforce apps, with the standards enterprises already integrate against.
Users, groups, and roles with joiner-mover-leaver flows and automated deprovisioning your auditors ask for by name.
Fine-grained roles and delegated administration — who can do what, scoped to the tenant and provable on demand.
An immutable, append-only trail. Access reviews and residency evidence exportable in a day, not a quarter.
MFA and risk-aware policies — step-up where it matters, out of the way where it doesn't.
A hardened, unforked Keycloak core under a platform layer we own — no black box, no lock-in tax.
Opleca is onboarding a small group of early-access partners across regulated and government-adjacent sectors in the Kingdom.
Request early access