Disrupt 2026Meet Himaya at TechCrunch Disrupt 2026. October 13–15 · Moscone West, San FranciscoBook time with us
Government and public sector

Workspace security built for government agencies and entities

Agentic email security, DLP and DSPM for agencies, ministries and public entities. Deployed in your government cloud or on-premise, with every action audited.

Governance

The controls agencies ask for

Connect agency identity, keep data in-country, and give oversight teams the evidence they need.

Identity and access

Sign in through SSO/SAML with enforced MFA. Least-privilege roles, and settings access that never has to include mail content.

Data stays in your boundary

Deploy in your AWS GovCloud or Azure Government VPC, or on-premise, so mail, files and models never leave infrastructure you control.

Audit trail

Every administrative action is logged, and every verdict carries a full reasoning trail for national security review.

Controlled data types

DLP and DSPM recognize ITAR, export-controlled and defense-marked content alongside citizen records and procurement data.

Deployment

Runs in your government cloud or on-premise

Himaya deploys inside your agency's AWS GovCloud or Azure Government VPC, or fully on-premise, so mail and data never leave your boundary.

AWS GovCloud or Azure Government

Government cloud VPC

  • Deploys into your AWS GovCloud or Azure Government account
  • Mail, files and models stay inside your accreditation boundary
  • Connects to your agency's Microsoft 365 or Google Workspace tenant
Runs in your data center

On-premise

  • Installed on infrastructure your agency owns and operates
  • Models trained on your agency's specific context
  • Custom security, compliance, and data-residency controls
Use cases

Protecting agency email and data

From spear phishing aimed at officials to controlled data slipping out by email or sitting overshared in agency drives, see how Himaya stops each one.

Government & Public SectorCloud Workspace Security

Protecting agencies, ministries, and public sector organizations across the cloud workspace, securing email, data, and identity against state-sponsored phishing, BEC, and espionage campaigns.

Real-World Use Cases

Spear Phishing Targeting Government Officials

Scenario

Ministers, diplomats, and senior officials receive highly targeted spear phishing crafted with publicly available information. These emails bypass standard filters because they contain no malicious attachments or links, just social engineering.

Example Implementation

  • Himaya Content Intelligence analyzes email language for impersonation patterns, urgency manipulation, and context-aware social engineering in Arabic and English
  • VIP Protection applied to ministers, deputy ministers, and department heads
  • Risk Orchestrator escalates ambiguous executive-targeted emails for deep semantic analysis Solution: Himaya catches social engineering attacks that pass every technical check

Potential Outcomes

  • Full threat reasoning audit trail for national security review
  • Zero successful spear phishing against senior officials

Built for the data and regulations you answer to

If this data moves through your agency's mail, or your mandate holds you to these frameworks, email is where exposure begins.

Sensitive data in agency mail

  • ITAR and export-controlled technical data
  • Defense and MOD protectively marked material
  • Citizen and resident records
  • Procurement and contract data

Compliance frameworks your agency answers to

Gulf / MENA

  • SAMA CSF
  • NCA ECC
  • UAE NESA
  • CBUAE
  • UAE PDPL
  • Saudi PDPL

United States

  • NIST CSF
  • HIPAA
  • SOC 2
  • CCPA

EU and international

  • GDPR
  • ISO 27001
  • DORA
  • NIS 2

Strengthen Public Services Security

Deploy sovereignty-aware controls and intelligence to you government email environment

Schedule Consultation

Overwatch

In-region analysts watching every agent

Forensics overwatch analysis pairs Himaya's autonomous agents with human review. Analysts observe agent verdicts, review escalations and tune detection to your agency's context.

US-person, cleared analysts

For US agencies, overwatch is delivered by US-person analysts who hold security clearances.

Gulf-resident analysts

For GCC government entities, overwatch is delivered by analysts resident in the Gulf, so review stays in-region.

FedRAMP experience

Analysts are experienced operating in FedRAMP environments and follow your agency's data handling rules.

Agents observed, not unchecked

Analysts review agent verdicts and escalations, and every action stays propose-only until your team approves it.

Review

Ready for government review

Compliance mapping, residency options and security documentation, in one place for your reviewers.

Compliance mapping

We adhere to FedRAMP and defense-related controls, and map workspace controls and evidence to the frameworks your program reports against.

  • FedRAMPFederal cloud security controlsAdheres
  • NIST SP 800-171Protecting controlled unclassified informationAdheres
  • CMMC 2.0Defense contractor cybersecurityAdheres
  • UAE PDPLUAE personal data protection lawMapped
  • Saudi PDPLSaudi personal data protection lawMapped
  • NCA ECCSaudi Essential Cybersecurity ControlsMapped
  • ISO 27001Information security managementMapped
  • SOC 2Service organization controlsIn progress
Trust Center

How we protect your data

The controls behind the platform. Full details, policies and our responsible disclosure program are in the Trust Center.

Encryption

TLS 1.2+ in transit and AES-256 at rest. Keys live in a dedicated KMS with scheduled rotation.

Tenant isolation

Each customer runs in a logically isolated tenant. Agent memory, data and models never cross tenant boundaries.

Your content stays yours

We process only what is needed to secure your workspace. Your content is never used to train shared models.

Monitoring and response

24/7 monitoring with automated detection, and a documented incident response plan with defined SLAs.

Frequently asked questions

Can Himaya run inside a government network?

Yes. Himaya deploys into your AWS GovCloud or Azure Government VPC, or on-premise, with custom security, compliance and data-residency controls.

Where is agency data processed?

Inside your AWS GovCloud or Azure Government VPC, or on-premise. Mail, files and models stay inside infrastructure you control.

Can Himaya detect ITAR and defense-marked data?

Yes. DLP inspects outbound messages and attachments, including scanned documents, for ITAR markings, export-control notices and protective markings, and DSPM finds the same content where it is stored and shared.

Who performs overwatch analysis?

It depends on where your agency operates. US agencies are served by US-person analysts with security clearances, experienced operating in FedRAMP environments. GCC government entities are served by analysts resident in the Gulf. For agencies in other countries, we assign analysts in line with your national data residency and personnel requirements. In every case, analysts review agent verdicts and escalations and tune detection to your agency.

How does Himaya protect ministers and senior officials?

VIP Protection is applied to ministers, deputy ministers and department heads, and ambiguous executive-targeted emails are escalated for deeper analysis.

Does Himaya analyze Arabic-language email?

Yes. Content Intelligence analyzes language for impersonation patterns, urgency manipulation and social engineering in Arabic and English.

What evidence can oversight teams review?

Every administrative action is logged, and every verdict carries a full reasoning trail. Our security policies are published in the Trust Center.

Which frameworks do you adhere to?

We adhere to FedRAMP, NIST SP 800-171 and CMMC 2.0 controls, and map workspace controls and evidence to UAE PDPL, Saudi PDPL, NCA ECC and ISO 27001. Our SOC 2 audit is in progress.

Talk to us about your agency's workspace

We will walk through deployment, residency and the evidence your reviewers need.