SecurePulsePhysical security assessment
Site assessments that show their working.
SecurePulse turns a physical security inspection into a structured, evidence-backed assessment. It builds the checklist for the site's emirate and sector, captures photo evidence on the walk, grades findings by severity, and produces a consulting-standard report that a named assessor signs off.
Energy-sector facility · Dubai
Physical security assessment
Illustrative
F-07HighSurveillance & monitoring · 8 points
Perimeter CCTV asserted as operational, but retention and test records not evidenced
What we observed: The checklist records continuous perimeter coverage across twelve cameras on the north boundary; no retention settings, alarm-test reports, or maintenance records were attached to evidence it.
Remediation: Immediate — attach retention settings and the latest alarm-test report; re-verify within 30 days.
Reviewer: Pending sign-off.
SecurePulseDetailed findings · 6 / 14
In the UAE, location decides the rulebook.
Physical security requirements in the UAE are set per emirate, not federally. A site in Dubai answers to a different authority stack than the same operator's site in Abu Dhabi or Sharjah, and critical infrastructure adds another layer again.
SecurePulse starts from the site's emirate and sector, and builds the assessment from there. Regulatory references are drawn from a maintained knowledge base rather than generated freely.
SecurePulse currently supports assessments for energy (oil and gas) sites and government buildings.
From site walk to signed report.
01
Scope the assessment
Capture the site's emirate, sector, and operating context. That intake decides which authorities and requirements apply.
02
Generate the checklist
SecurePulse produces an assessment checklist organised across ten physical security domains and tailored to the site rather than pulled from a generic template.
03
Walk the site
Assessors work the checklist on a phone or tablet, recording status and notes, and attaching photo evidence against individual items.
04
Draft findings
Findings are raised only where there is a genuine gap or uncertainty, categorised by domain, numbered, and graded Critical, High, Medium, Low, or Informational.
05
Review, sign off, export
A lead assessor and reviewer approve the assessment before it becomes a report. The output exports to PDF or Word for the client file.
Ten domains, assessed consistently.
Every assessment is organised across the same domains, so findings can be compared between sites and across time.
- 01Perimeter security
- 02Access control
- 03Surveillance & monitoring
- 04Intrusion detection
- 05Security personnel
- 06Environmental & physical controls
- 07Internal zones & segregation
- 08Policies & procedures
- 09Supply chain & delivery
- 10Incident response & recovery
Every regulatory claim carries its confidence.
UAE physical security guidance is unevenly published. Some requirements are set out in enacted law; some are only visible through approved installers and industry sources; some are genuinely unresolved.
SecurePulse labels each regulatory reference with the strength of the evidence behind it, and it is not permitted to present an unresolved item as a probable requirement. Where the answer is not established, the assessment says so and escalates it to the competent authority.
Requirement mappingIllustrative
Continuous perimeter lighting at the site boundary
VERIFIEDHigh
Applies to the site — confirmed from the authority's enacted framework
CCTV retention minimums for restricted areas
PARTIALMedium
Applies — technical minimums to be confirmed against the current manual
Operator-specific design standards
GAPHigh
Unresolved — escalated to the competent authority, not assumed
- VERIFIED
- Confirmed from enacted legislation, an official authority portal, or a standards body.
- PARTIAL
- Supported by reputable secondary sources, but the primary source was not independently confirmed.
- INFERRED
- Derived from consistent cross-referencing; no single primary source.
- GAP
- Unresolved. Stated as unresolved and escalated — never presented as a likely requirement.
A report a consultant would recognise.
After the walk, the checklist, and the review, leadership receives a document — the sections an assessment report is expected to contain, in a consistent structure, exportable to PDF or Word.
Physical security assessment report
- 01Assessment summary and risk scorecard
- 02Findings by domain
- 03Detailed findings with severity
- 04Risk matrix
- 05Compensating controls
- 06Indicative compliance mapping
- 07Recommendations roadmap
- 08Assumptions and information gaps
- 09Sign-off and attestation
Sign-off
- Prepared by
- SecurePulse — draft
- Lead assessor
- Named sign-off
- Reviewer
- Approved for issue
Risk scorecardIllustrative
SecurePulse drafts. People decide.
SecurePulse is professional advisory tooling. It is not a regulatory audit, a legal opinion, or a certification, and it does not replace a qualified security assessor.
Findings are drafts until a lead assessor and a reviewer accept them. Every report carries a named sign-off, records that it is a point-in-time assessment, and instructs the reader to verify regulatory references with the competent authority.
Where SecurePulse applies.
UAE & Gulf
Physical security assessment
Emirate- and sector-aware site assessments for energy and government facilities. The checklist, the evidence rules and the severity model are built for those sites; SecurePulse is not a general-purpose audit tool.
Looking for regulatory compliance?
That is a different Kaibre product
Tuntas reads a new Indonesian financial regulation against a company's own documents and returns the position obligation by obligation. Different work, different buyer, its own product.
TuntasWhere SecurePulse is today
SecurePulse is in active development and demonstration with organisations in the UAE and the wider Gulf. If you assess physical security for regulated or high-consequence sites, we would like to show you the current build and hear where it breaks.