Skip to content

Pillar II · Secure & Scale · 04

An in-Kingdom cloud — Google Cloud, AWS, Azure.

The cloud should be cheaper, faster and safer than the on-premise estate it replaces — and, increasingly in Saudi Arabia, it should run on in-Kingdom infrastructure. We land workloads on Google Cloud's Saudi region for data-residency by default, on AWS where the data-services catalogue calls for it, and on Azure where Microsoft 365 and Entra are already core. Architected for your regulatory envelope, migrated in waves, operated by the same team.

Providers we land on

In-Kingdom Google Cloud — residency by default.

Since Google Cloud's Saudi region went live, in-Kingdom residency is a practical choice — not just a policy. We land the data-sensitive workload on Google, pick the adjacent clouds where their strengths apply, and run the landing zones in one architecture discipline.

Google Cloud

KSA region · live

In-Kingdom Saudi region · data residency by default

KSA regionGKEBigQueryVertex AICloud SQLAnthos
Best fit: Best for in-Kingdom data residency, analytics and AI workloads on a KSA-hosted cloud.

AWS

Broadest service catalogue, strongest data services

Landing ZoneControl TowerTransit GatewayEKSRDSS3
Best fit: Best for data-heavy, multi-account enterprises and regulated workloads.

Microsoft Azure

Where Microsoft 365 and Entra are already core

Landing ZoneEntra IDAKSAzure SQL
Best fit: Best where Microsoft 365, Power Platform or on-prem AD are already in place.

Oracle Cloud

Oracle database and Fusion workloads

OCI LZAutonomous DBFusion Apps
Best fit: Best when the estate is already Oracle-heavy — Fusion, EBS or Autonomous DB.

Migration waves

The sequence. Nothing big-bang.

Wave 0Foundation

Landing zone, identity, logging, baseline guardrails

Wave 1Lift & shift

Rehost non-critical workloads. Measure before refactoring.

Wave 2Replatform

Managed services, containerization, CI/CD, observability.

Wave 3Refactor & build

Event-driven, serverless, cloud-native where it earns it.

In-Kingdom residency

Google Cloud in the Kingdom — a region you can actually land on.

With Google Cloud's Saudi region live, enterprises can run regulated workloads inside the Kingdom — no more residency-by-contract. We design the landing zone to keep data inside the region by default, with clear routing rules for anything that has to leave.

Google Cloud · KSA region · liveIn-Kingdom data residency
Residency policies
  • Google Cloud KSA as primary region for sensitive workloads
  • Customer-managed keys + HSM options (Cloud KMS)
  • Private endpoints, VPC Service Controls and routing rules
  • Per-workload residency tags and enforcement
  • Audit trails of cross-region data access

Practical questions

The architecture conversation, compressed.

Which cloud do you recommend?

The one that fits your workloads, your licensing, your data-residency constraints and your existing skills. We're active across AWS, Azure and Oracle Cloud — and often deliver multi-cloud landing zones.

Stuck with cloud bills and no architecture? Let's fix it.

We typically deliver a landing-zone prototype and a waved migration plan in the first three weeks.

Talk to our cloud team