Skip to content
nuhaa.ai

Enterprise

Built in Saudi. Designed for enterprise trust.

Before an organization in the Kingdom adopts AI, four questions have to be answered honestly: where does the data go, who can see what, what happens to it, and what have you actually been measured against. This section answers them.

  • Saudi-built
  • Hosted in-Kingdom
  • On-prem ready

Sovereign by design

The usual trade in enterprise AI is capability in exchange for sending your material somewhere else. nuhaa.ai was built the other way round: the inference runs where your organization can point at it, and the isolation between organizations is a property of the architecture rather than a promise in a contract.

  • Models served from infrastructure inside Saudi Arabia.
  • Content never sent to a third party model provider.
  • Each organization isolated, and never used to train another’s model.

Built against

The standards the work was measured against.

Security was assessed against published frameworks rather than an internal checklist, in both the cloud and on premises editions.

  • Assessed against

    OWASP Top 10:2025

    Web application risks, mapped control by control

  • Assessed against

    OWASP Agentic 2026

    Prompt injection, tool abuse and delegation limits

  • Assessed against

    OWASP ASVS 5.0

    Verification standard at Level 2

  • Assessed against

    CWE / SANS Top 25

    The most dangerous software weaknesses

  • Assessed against

    MITRE ATT&CK

    Adversary techniques used to shape detection

  • Assessed against

    Saudi PDPL

    Personal data protection law of the Kingdom

  • Assessed against

    CST RS10

    Cloud computing regulatory framework and residency

  • Control mapping

    SOC 2 TSC

    Trust services criteria, control mapping documented

  • Control mapping

    ISO 27001:2022

    Annex A families, control mapping documented

Assessed against means the platform was reviewed under that framework and the findings closed. Control mapping means the controls are documented against the standard; nuhaa.ai is not certified under SOC 2 or ISO 27001, and the mapping is available on customer engagement.

For the evaluation pack

What we can put in front of your review board.

These are the artefacts an enterprise or government evaluation usually asks for. They are available on engagement, under NDA where appropriate.

  • Security architecture and data flow documentation
  • Control mapping against SOC 2 trust services criteria and ISO 27001 Annex A
  • PDPL processing description and data handling summary
  • Deployment topology for cloud and on-premise
  • Model card describing the systems that generate answers
  • AI ethics documentation covering intended use and known limitations

nuhaa.ai is not certified under SOC 2 or ISO 27001. What exists is a documented mapping of controls, and we describe it that way everywhere.

We would rather answer the hard questions early than discover them at procurement.