Who we are

About IT Horizon

A boutique technology house engineering enterprise systems with the precision of a luxury maison.

Our story
Odoo Partner

Comprehensive Odoo

End-to-end Odoo 20 Enterprise, implemented, customized, integrated and supported by certified specialists.

Become a client
Odoo apps

Every app, configured for the Gulf

Finance, sales, supply chain, HR, marketing and services apps implemented with the local tax, payroll and language rules each country needs.

All Odoo apps
What we do

Beyond ERP

Strategy, product engineering and customer-experience work that turns systems into advantage.

Talk to us
Sectors

Industry depth

Domain fluency across the sectors that define the GCC economy, and the regulations behind them.

Discuss your sector
Learn · grow · succeed

Insights

Real-world ideas, case studies and sessions to help your business work smarter with Odoo.

Browse the blog
Contact usBook a consultation
Cybersecurity and compliance

Your ERP holds everything. We keep it locked.

Payroll, contracts, prices, customer records: an ERP concentrates the data a business can least afford to lose. We harden Odoo and the platforms around it, prove it with testing, and keep it that way with monitoring and backups you can actually restore from.

What we cover

Security work that holds up to an audit.

Each area below is delivered as a documented control, with evidence your auditors and your board can read.

01

Odoo hardening

Secure configuration, record rules, field-level access, two-factor login and session policies across every company in the database.

02

Infrastructure security

Hardened Linux hosts, firewalls, TLS everywhere, Cloudflare WAF and rate limiting in front of Odoo, portals and APIs.

03

Penetration testing

Application and infrastructure testing against OWASP and CIS baselines, with a prioritised fix list and a retest.

04

Backups and recovery

Encrypted daily backups in a second region, retention policies and restore drills with measured recovery times.

05

Monitoring and response

Log collection, alerting on suspicious logins and data exports, and a written incident response plan your team has rehearsed.

06

Compliance mapping

Controls mapped to CITRA guidance in Kuwait, NCA ECC in Saudi Arabia, UAE and Egyptian data protection law, and ISO 27001 readiness.

Regulators here now expect proof, and so do your largest customers.
Why it matters in the Gulf

Regulators here now expect proof, and so do your largest customers.

Government tenders in Kuwait and Saudi Arabia increasingly ask suppliers for evidence of security controls. Banks and large groups do the same before they connect their systems to yours. A security programme built into the ERP from day one answers those questions once, instead of scrambling before every contract.

Because we build the Odoo modules, portals and integrations ourselves, security is designed into the code and the hosting rather than bolted on afterwards.

  • Role-based access and audit trails on every module
  • Encrypted backups tested by real restores
  • Penetration test reports you can share with clients
  • Data kept in the region your regulator requires
How a review runs

From assessment to a hardened, monitored platform.

01

Assess

Inventory of systems, data flows, users and current controls, with a risk register.

02

Harden

Fix configuration, access, hosting and code findings in priority order.

03

Prove

Penetration test, restore drill and documented evidence for each control.

04

Monitor

Alerting, monthly reviews and patching as part of your support agreement.

100%of our hosted Odoo databases on encrypted daily backups
2FAenforced for every administrator account we manage
24hcritical security patch window on supported platforms
GCCand Egypt data residency options
FAQ

Questions, answered.

Yes. We start with an assessment of the existing database, custom modules and hosting, then fix findings in priority order. Many engagements begin this way.

Odoo.sh gives you a well-run platform, but access rules, record permissions, custom code and integrations are still your responsibility. That is where most real-world exposure sits, and that is what we harden.

CITRA guidance and the data classification policy in Kuwait, NCA Essential Cybersecurity Controls in Saudi Arabia, UAE federal data protection law, Egypt’s Personal Data Protection Law, and ISO 27001 as a general framework.

Yes, for applications we built and for others. You receive a findings report with severity ratings, fix guidance and a retest once the fixes are deployed.

That depends on the plan we agree. We measure it during restore drills and write the recovery time into your support agreement rather than estimating it.

Find out where you stand before someone else does.

A security review of your Odoo and connected platforms, with a prioritised plan you can act on.