WW-Enterprises

W-Enterprises/Saudi Arabia

Kingdom of Saudi Arabia / Gulf Cooperation Council

Built for the Gulf, not translated for it.

Most developers who can build the software cannot do Arabic typography properly. Most who can do Arabic are not shipping Cloud Run with signed webhook verification and a data-residency posture that survives a compliance review. The overlap is small. This practice sits in it.

هندسة برمجيات وذكاء اصطناعي للسوق الخليجي ←

Production
Live Saudi systems taking real payments
34+
Bilingual document templates shipped
93.5%
Field extraction accuracy, AI invoice parsing
UTC+2
Cape Town, overlapping the Gulf working day

The four things that actually stop projects

Every Saudi software project that goes wrong tends to go wrong on the same four things, and none of them are the application logic.

01 / Language

Arabic that is correct, not approximated

Bidirectional text where Arabic and Latin script mix in one line. Numerals in the convention the document requires. Fonts with genuine Arabic coverage, embedded and awaited before a PDF is rendered. A right-to-left interface that mirrors properly rather than being visually flipped. Every one of these is a separate bug the first time it is met.

02 / Data

PDPL, treated as architecture

The Personal Data Protection Law reaches processing of Saudi residents' data by entities outside the Kingdom, so a foreign supplier is in scope by default. The clean answer is to build as a processor, keep production data in a Saudi region, hold nothing sensitive that does not need holding, and document transfers properly where they exist.

03 / Money

Payments that settle, in the local rails

Geidea hosted checkout with Apple Pay, signed webhook verification and tokenised recurring billing, running in production. Moyasar integrated. Stripe and PayPal for cross-border. A card flow that works in a demo and fails on a real mada card is not an integration.

04 / Compliance

ZATCA and the labour platforms

Invoicing flows built with ZATCA Phase 2 requirements in mind, and HR document flows that reflect how Saudi employers actually operate against Qiwa, GOSI and wage-protection obligations. Full detail on ZATCA integration.

Where the demand is right now

Two forced-purchase events are driving Saudi software spend in the second half of 2026, and neither depends on discretionary budget.

E-invoicing, deadline 1 February 2027

ZATCA Wave 25 reaches every taxpayer above SAR 187,500 in revenue. Because that figure is also the voluntary VAT registration threshold, Wave 25 is effectively the last rung. The correct advice for most businesses is not to replace their invoicing product but to integrate the one they have. What Phase 2 requires, and where integrations fail.

Labour and HR compliance, already live

Employment contract documentation on Qiwa now feeds directly into Saudization calculations, wage clauses in employment contracts became enforceable through a phased schedule running into 2026, and a new Nitaqat phase runs to 2028 with profession-level quotas that reach employers with only a handful of staff. The result is that a Saudi employer's paperwork obligations are now too intricate to run from a spreadsheet, and much of the HR technology in the market is deployed in-house, which means integration work rather than seats.

This is the market the shipped work sits in. See the bilingual HR document platform case study.

A note on what is not driving demand

Venture funding into Saudi startups fell sharply through the first half of 2026, and enterprise software took a small share of what remained. Selling into funded startups is the wrong plan this year. Selling into businesses with a regulatory deadline is the right one, because the buyer has already decided to solve the problem and is only choosing who solves it.

What can be built

  • Bilingual document generation platforms. Multi-tenant, template-driven, server-rendered to PDF, with nothing sensitive persisted. HR contracts and letters, statements, certificates, offer letters, invoices.
  • ZATCA Phase 2 integration and remediation. Fatoora onboarding, clearance and reporting, hash chain and counter integrity, TLV QR, XAdES signing.
  • AI document extraction. OCR combined with large language model normalisation for invoices and forms, in Arabic and English, with a review workflow rather than blind automation.
  • Multi-tenant SaaS end to end. Tenant isolation, roles, subscription billing on local rails, admin tooling, identity.
  • Subcontract engineering capacity. Delivered under an ERP partner's or consultancy's own name, for firms carrying more backlog than build capacity.

How this works from outside the Kingdom

The practice is based in Cape Town at UTC+2, one hour behind Riyadh, which means a full overlapping working day rather than a handover window. Delivery is remote and has been since the first Saudi engagement.

Three points that matter commercially and are worth settling before a contract is signed rather than after:

  • Hosting. Production in a Saudi region on the client's own cloud account is the default recommendation. It resolves the data-residency question, the PDPL transfer question and most procurement objections at once, and it leaves the client owning their own infrastructure.
  • Contract characterisation. Saudi withholding tax treats custom software development differently from a licence to reproduce or resell software. How the contract is worded has a direct effect on the net figure, for both sides. Agree it explicitly.
  • Reusable materials. Pre-existing tools, libraries and methodologies are declared in a schedule at signature, licensed to the client, and not claimed as bespoke work. Custom-developed code transfers on full payment. Both sides know exactly what they own.

Common questions

Can a supplier outside Saudi Arabia build a PDPL-compliant system?

Yes, and the law applies to that supplier anyway, because it reaches processing of data relating to individuals residing in the Kingdom by entities outside it. The practical approach is to act as a processor rather than a controller, host production data in a Saudi region, keep development and testing on pseudonymised or synthetic data, and put the Saudi standard contractual clauses and a transfer risk assessment in place for anything that genuinely has to leave.

What does Arabic-first actually mean?

That the data model, templates and layout engine treat Arabic as a first-class language rather than a translation layer. Bidirectional text handled correctly where scripts mix, numerals in the right convention, fonts with real Arabic coverage embedded and awaited before rendering, and an interface that mirrors under right-to-left rather than being visually flipped.

Which Saudi payment providers are supported?

Geidea hosted checkout including Apple Pay, with signed webhook verification and tokenised recurring billing, is running in production. Moyasar has also been integrated. Stripe and PayPal are used where the buyer sits outside the Gulf.

Is a Saudi regional headquarters required?

For private-sector contracts, no. For government contracts the regional headquarters requirement applies with published exemptions, and contracts valued at SAR 1 million or less fall outside those controls entirely. Confirm the current position with the Local Content and Government Procurement Authority before bidding.

Can the client name be used as a reference?

Only with permission. Gulf engagements are credited by sector and region unless the client agrees to be named. Portfolio and marketing rights are agreed in the proposal rather than assumed.

Building something for the Saudi market?

Send what you are building, when it needs to ship, and what compliance obligations sit behind it. You will get a senior read on scope and risk within one working day.

Regulatory statements on this page reflect published Saudi sources checked in August 2026 and are orientation, not legal or tax advice. Requirements change. Confirm your own position with the relevant authority or a qualified Saudi adviser.