Enterprise
Built in Saudi. Designed for enterprise trust.
Before an organization in the Kingdom adopts AI, four questions have to be answered honestly: where does the data go, who can see what, what happens to it, and what have you actually been measured against. This section answers them.
- Saudi-built
- Hosted in-Kingdom
- On-prem ready
The four things a buyer evaluates
Enterprise readiness, in four sections.
Security and governance
Tenant isolation, permission-aware answers, read-only data access, and an audit trail administrators can review.
Read moreSovereign AI
The models that answer your questions run on infrastructure inside the Kingdom, on content that is never sent to a third party provider.
Read moreDeployment
Managed cloud in the Kingdom, private cloud, or inside your own perimeter including air-gapped installations.
Read morePDPL and compliance
Designed to support the obligations the law places on you, with the standards it has been assessed against stated plainly.
Read more
Sovereign by design
The usual trade in enterprise AI is capability in exchange for sending your material somewhere else. nuhaa.ai was built the other way round: the inference runs where your organization can point at it, and the isolation between organizations is a property of the architecture rather than a promise in a contract.
- Models served from infrastructure inside Saudi Arabia.
- Content never sent to a third party model provider.
- Each organization isolated, and never used to train another’s model.

Built against
The standards the work was measured against.
Security was assessed against published frameworks rather than an internal checklist, in both the cloud and on premises editions.
- Assessed against
OWASP Top 10:2025
Web application risks, mapped control by control
- Assessed against
OWASP Agentic 2026
Prompt injection, tool abuse and delegation limits
- Assessed against
OWASP ASVS 5.0
Verification standard at Level 2
- Assessed against
CWE / SANS Top 25
The most dangerous software weaknesses
- Assessed against
MITRE ATT&CK
Adversary techniques used to shape detection
- Assessed against
Saudi PDPL
Personal data protection law of the Kingdom
- Assessed against
CST RS10
Cloud computing regulatory framework and residency
- Control mapping
SOC 2 TSC
Trust services criteria, control mapping documented
- Control mapping
ISO 27001:2022
Annex A families, control mapping documented
Assessed against means the platform was reviewed under that framework and the findings closed. Control mapping means the controls are documented against the standard; nuhaa.ai is not certified under SOC 2 or ISO 27001, and the mapping is available on customer engagement.
For the evaluation pack
What we can put in front of your review board.
These are the artefacts an enterprise or government evaluation usually asks for. They are available on engagement, under NDA where appropriate.
- Security architecture and data flow documentation
- Control mapping against SOC 2 trust services criteria and ISO 27001 Annex A
- PDPL processing description and data handling summary
- Deployment topology for cloud and on-premise
- Model card describing the systems that generate answers
- AI ethics documentation covering intended use and known limitations
nuhaa.ai is not certified under SOC 2 or ISO 27001. What exists is a documented mapping of controls, and we describe it that way everywhere.
We would rather answer the hard questions early than discover them at procurement.