PDPL and compliance
Designed to support PDPL requirements.
The Personal Data Protection Law places obligations on your organization, not on your software vendor. What a platform can do is make those obligations practical to meet. Here is exactly what nuhaa.ai does, and what it does not claim.
The honest version
No software product is PDPL compliant on your behalf. The law applies to the organization processing the personal data, and a vendor claiming otherwise is either confused or selling something. What a platform can do is avoid getting in the way: keep the data where the law expects it, make access decisions explicit, keep a record of what happened, and make deletion and export something you can actually perform.
nuhaa.ai is designed against those requirements. Data residency is architectural rather than configurable, access follows your own permission model, every question and response is recorded for review, and an organization’s content can be removed on request. Where the platform cannot help, the honest answer is on this page rather than in a footnote.
How the platform supports the obligations
Seven things that make PDPL practical.
- Residency. Content and inference stay inside the Kingdom, or inside your own perimeter for on-premise deployments.
- Purpose limitation. Your content is used to answer your organization’s questions and nothing else. It is never used to train a model another customer benefits from.
- Access control. What a person can reach through nuhaa.ai is bounded by the permissions your organization already gave them.
- Records of processing. Questions, sources and responses are recorded, so a processing activity can be described rather than reconstructed.
- Minimization. Only the sources needed for a use case are connected, one at a time, with your approval.
- Erasure and export. An organization’s content can be removed or exported on request, including the derived index built from it.
- Sub-processors. The model that answers your questions is not a third party service, so the usual chain of external processors is not part of the answer path.
This describes how the platform is built. Whether your particular processing is lawful is a question for your own privacy office, and we will support that review rather than pre-empt it.
Read the wording carefully
Certified, assessed and mapped are three different things.
A lot of enterprise AI marketing blurs these deliberately. We would rather you knew which one applies.
Certified
An accredited body has audited the organization and issued a certificate. nuhaa.ai holds no certifications today. Where you see that word on this site, it is describing what we are not.
Assessed against
The platform was reviewed under a published framework and the findings were closed. This is true of OWASP Top 10, OWASP ASVS, the CWE/SANS Top 25 and the Saudi PDPL.
Control mapping
Controls are documented against a standard’s criteria without an external audit. This is what exists for SOC 2 and ISO 27001, and it is available on engagement.
Built against
The standards the work was measured against.
Security was assessed against published frameworks rather than an internal checklist, in both the cloud and on premises editions.
- Assessed against
OWASP Top 10:2025
Web application risks, mapped control by control
- Assessed against
OWASP Agentic 2026
Prompt injection, tool abuse and delegation limits
- Assessed against
OWASP ASVS 5.0
Verification standard at Level 2
- Assessed against
CWE / SANS Top 25
The most dangerous software weaknesses
- Assessed against
MITRE ATT&CK
Adversary techniques used to shape detection
- Assessed against
Saudi PDPL
Personal data protection law of the Kingdom
- Assessed against
CST RS10
Cloud computing regulatory framework and residency
- Control mapping
SOC 2 TSC
Trust services criteria, control mapping documented
- Control mapping
ISO 27001:2022
Annex A families, control mapping documented
Assessed against means the platform was reviewed under that framework and the findings closed. Control mapping means the controls are documented against the standard; nuhaa.ai is not certified under SOC 2 or ISO 27001, and the mapping is available on customer engagement.
The questions they will ask are the ones we would rather answer early.