Skip to content
nuhaa.ai

PDPL and compliance

Designed to support PDPL requirements.

The Personal Data Protection Law places obligations on your organization, not on your software vendor. What a platform can do is make those obligations practical to meet. Here is exactly what nuhaa.ai does, and what it does not claim.

The honest version

No software product is PDPL compliant on your behalf. The law applies to the organization processing the personal data, and a vendor claiming otherwise is either confused or selling something. What a platform can do is avoid getting in the way: keep the data where the law expects it, make access decisions explicit, keep a record of what happened, and make deletion and export something you can actually perform.

nuhaa.ai is designed against those requirements. Data residency is architectural rather than configurable, access follows your own permission model, every question and response is recorded for review, and an organization’s content can be removed on request. Where the platform cannot help, the honest answer is on this page rather than in a footnote.

How the platform supports the obligations

Seven things that make PDPL practical.

  • Residency. Content and inference stay inside the Kingdom, or inside your own perimeter for on-premise deployments.
  • Purpose limitation. Your content is used to answer your organization’s questions and nothing else. It is never used to train a model another customer benefits from.
  • Access control. What a person can reach through nuhaa.ai is bounded by the permissions your organization already gave them.
  • Records of processing. Questions, sources and responses are recorded, so a processing activity can be described rather than reconstructed.
  • Minimization. Only the sources needed for a use case are connected, one at a time, with your approval.
  • Erasure and export. An organization’s content can be removed or exported on request, including the derived index built from it.
  • Sub-processors. The model that answers your questions is not a third party service, so the usual chain of external processors is not part of the answer path.

This describes how the platform is built. Whether your particular processing is lawful is a question for your own privacy office, and we will support that review rather than pre-empt it.

Read the wording carefully

Certified, assessed and mapped are three different things.

A lot of enterprise AI marketing blurs these deliberately. We would rather you knew which one applies.

  • Certified

    An accredited body has audited the organization and issued a certificate. nuhaa.ai holds no certifications today. Where you see that word on this site, it is describing what we are not.

  • Assessed against

    The platform was reviewed under a published framework and the findings were closed. This is true of OWASP Top 10, OWASP ASVS, the CWE/SANS Top 25 and the Saudi PDPL.

  • Control mapping

    Controls are documented against a standard’s criteria without an external audit. This is what exists for SOC 2 and ISO 27001, and it is available on engagement.

Built against

The standards the work was measured against.

Security was assessed against published frameworks rather than an internal checklist, in both the cloud and on premises editions.

  • Assessed against

    OWASP Top 10:2025

    Web application risks, mapped control by control

  • Assessed against

    OWASP Agentic 2026

    Prompt injection, tool abuse and delegation limits

  • Assessed against

    OWASP ASVS 5.0

    Verification standard at Level 2

  • Assessed against

    CWE / SANS Top 25

    The most dangerous software weaknesses

  • Assessed against

    MITRE ATT&CK

    Adversary techniques used to shape detection

  • Assessed against

    Saudi PDPL

    Personal data protection law of the Kingdom

  • Assessed against

    CST RS10

    Cloud computing regulatory framework and residency

  • Control mapping

    SOC 2 TSC

    Trust services criteria, control mapping documented

  • Control mapping

    ISO 27001:2022

    Annex A families, control mapping documented

Assessed against means the platform was reviewed under that framework and the findings closed. Control mapping means the controls are documented against the standard; nuhaa.ai is not certified under SOC 2 or ISO 27001, and the mapping is available on customer engagement.

The questions they will ask are the ones we would rather answer early.