Industry 01 / 05

Banking. Approved content, in context.

Govern approved banking guidance across fast-changing in-app customer journeys.

Banking content must respond to account context, application status and seasonal demand without waiting for every app release. Teams also need consistent Arabic and English guidance with controlled eligibility, review and publishing.

Hosted in Riyadh today. In-Kingdom-only is an Enterprise agreement, not a switch.Consent controlsREST API todaySDKs in preview
Banking context
ContextIllustrative
ApplicationAccount opening started
Products heldCard, salary account
LanguageArabic or English
Banking

Approved content, in context.

How it runs

One change, end to end.

01 What the app already knows
Context
Read at runtime
ApplicationAccount opening started
Products heldCard, salary account
LanguageArabic or English
Rules decide
02 A reviewed content change
Home card block
Approved
Reviewers2 of 2
AudienceSalaried, Riyadh
ReleaseNot required
Renders
03 In the banking app
9:41
Wathiq BankN
Good morning, Noura
Current accountSAR ••••••Account ••4471
Your new card has arrivedActivate it in the app and tap to pay today.Activate card
Your June statement is ready to view
Beneficiary added and approved

Illustrative interface content. It shows what the platform supports, not a bank configuration.

The pressure

What makes it hard.

01

Regulated content changes

Financing, fee and servicing copy may change quickly, while review and release controls must remain clear under regulator scrutiny.

02

Arabic servicing clarity

Arabic-first customers need precise, approved guidance across onboarding, beneficiary management and account servicing flows.

03

Ramadan demand windows

Financing campaigns around Ramadan require exact schedules, audience rules and clear expiry controls.

What teams build

Four things a team could build.

The products behind it

What does the work.

Data, hosting and compliance

Residency, certification and SAMA.

Data residency. Today ContentFlow runs as a single deployment on infrastructure located in Riyadh, Saudi Arabia, so production content and end-user data are processed in the Kingdom; that is a property of how we are currently deployed rather than a control the product enforces, encrypted backups and some third-party processors are handled outside the Kingdom, and an in-Kingdom-only arrangement is something we agree in writing on an Enterprise plan rather than something this page can promise.

Certifications. Our controls are built around the requirements of the Saudi PDPL. Backups are encrypted with AES-256 and restore-tested. HTTPS is enforced across the site. SOC 2 Type II and ISO 27001 are planned.

Production integration today uses the REST API. Native SDKs for React Native, iOS, Android and Web are in preview and are not generally available. The @contentflow/cli package is not published yet.

One engineering integration up front. After that your team publishes content changes without a new app build and without a new app store submission.

Publishing content through ContentFlow does not require a new build or a new store submission. Any change to your app's own code still goes through Apple and Google review, and remotely delivered content has to stay inside the purpose your app already declares and the store policies that apply to it.

SAMA. ContentFlow has not been assessed against SAMA's outsourcing or cloud computing rules and does not claim compliance with them. Those rules sit with you as the regulated entity. What we can put in front of your assessment is the deployment location, the sub-processors involved, the data flows, the retention behaviour and the access controls in place; ask and we will send them.

The Free plan is for evaluation. Our terms do not permit real production, personal or regulated end-user data in evaluation or sandbox environments, so a pilot carrying real customer data runs under a signed agreement.

Questions

What teams ask.

Can business teams update guidance without an app release?

Yes, once the relevant placement is integrated, approved content can be updated remotely while the bank's application retains control of rendering. Publishing content this way does not require a new build or a new store submission; a change to the bank's own app code still goes through Apple and Google review.

How does the bank integrate Contentflow?

Production integration today uses the REST API. Native SDKs for React Native, iOS, Android and Web are in preview and are not generally available. The @contentflow/cli package is not published yet.

Does in-Kingdom deployment make the bank compliant?

No. ContentFlow runs today as a single deployment on infrastructure located in Riyadh, so production data is processed in the Kingdom, but that is a property of how we are currently deployed rather than a control the product enforces; encrypted backups and some third-party processors are handled outside the Kingdom. ContentFlow holds no third-party security certification today. Compliance with PDPL, SAMA and other regulatory obligations depends on the bank's own implementation, contracts and governance, not on ContentFlow.

Part of one platform

Five sectors, one platform.

Production integration today uses the REST API. Native SDKs for React Native, iOS, Android and Web are in preview and are not generally available. The @contentflow/cli package is not published yet.