Tamara is Saudi Arabia's first fintech unicorn, founded in 2020, operating a Sharia-compliant Buy Now Pay Later platform across the GCC. With over 20 million users, the company processes financial transactions at scale - which means a threat surface that spans payment fraud, account takeover, transaction manipulation, and regulatory compliance across multiple jurisdictions. The platform lets customers split purchases into up to 24 monthly payments with no late fees, requiring robust anti-fraud systems, identity verification pipelines, and real-time risk scoring.
The company is building out a financial super-app, expanding the attack surface into new product domains beyond BNPL. For a security team, this means threat modeling isn't static - it grows with every feature launch. The fintech operates in a regulatory environment shaped by Saudi Arabia's financial authorities and Sharia compliance requirements, adding layers of compliance-driven security controls on top of standard financial services protections. Sensitive PII and payment data handling are central to the platform's operations.
Tamara's stated pillars - trust, simplicity, and ubiquity - signal a company where security isn't just a technical requirement but existential to the business model. A breach or fraud spike at 20 million users isn't an incident; it's a headline. The team building this operates across Saudi Arabia and the wider GCC, with infrastructure that needs to support high-availability payment processing, merchant integrations, and a consumer-facing app ecosystem that's still scaling.




