Security and governance
Intelligence you can check, not just trust.
An answer nobody can verify is a liability, not an asset. Four properties separate an enterprise AI answer from a confident sentence, and each of them is enforced rather than encouraged.
The trust model
Grounded. Governed. Traceable. Responsible.
Grounded
Answers are based on trusted enterprise sources. Where the sources do not support an answer, nuhaa.ai says so instead of filling the gap.
Governed
Access follows your role, department and ownership model. What a person can reach through nuhaa.ai is what they could already reach without it.
Traceable
Responses carry their sources, and administrators can review what was asked and what was returned.
Responsible
Content policies, human review paths and clear boundaries are built in, so adoption stays controlled as usage grows.
Controls
What is enforced on every request.
- Tenant isolation. Every query that touches organizational data is bound to one organization before it runs, and a request can never resolve to another organization’s content.
- Permission-aware retrieval. The asker’s entitlements are resolved on the server and applied before anything is retrieved, not filtered out of the answer afterwards.
- Read-only data access. Queries generated against your databases are restricted to reads. Anything that would modify a record is refused before execution.
- Untrusted content is data, not instruction. Text arriving from a document, a tool or the web is never treated as a command to the system.
- Encrypted secrets. Credentials and connection details are encrypted at rest, and tokens and secrets are never written to logs.
- Content policy on input and output, applied in both Arabic and English.
- Audit trail. Questions, sources and responses are recorded for administrator review.
Built against
The standards the work was measured against.
Security was assessed against published frameworks rather than an internal checklist, in both the cloud and on premises editions.
- Assessed against
OWASP Top 10:2025
Web application risks, mapped control by control
- Assessed against
OWASP Agentic 2026
Prompt injection, tool abuse and delegation limits
- Assessed against
OWASP ASVS 5.0
Verification standard at Level 2
- Assessed against
CWE / SANS Top 25
The most dangerous software weaknesses
- Assessed against
MITRE ATT&CK
Adversary techniques used to shape detection
- Assessed against
Saudi PDPL
Personal data protection law of the Kingdom
- Assessed against
CST RS10
Cloud computing regulatory framework and residency
- Control mapping
SOC 2 TSC
Trust services criteria, control mapping documented
- Control mapping
ISO 27001:2022
Annex A families, control mapping documented
Assessed against means the platform was reviewed under that framework and the findings closed. Control mapping means the controls are documented against the standard; nuhaa.ai is not certified under SOC 2 or ISO 27001, and the mapping is available on customer engagement.
How it is built
Every feature that touches organizational data is reviewed against the same four questions before it is written: is the tenant boundary enforced, is the route authorized, is the untrusted input handled as data, and does anything sensitive reach a log. New attack surface arrives with a test that proves the control holds.
The platform is assessed against published frameworks rather than an internal checklist, and the findings are closed rather than filed. Both editions are covered: the multi-tenant cloud service and the single-tenant on-premise build, which cannot enable cloud-only features even if it is configured to try.
Code produced by the platform runs only inside a hardened sandbox, and the models that generate answers have no ability to act on your systems as a side effect of a question. nuhaa.ai proposes. People execute.
We will answer it directly, and tell you where the answer is no.