Skip to content
nuhaa.ai

Resources

Three documents your security team will ask for anyway.

A demo is a 45-minute commitment. These are for the part before that: the evidence a champion forwards internally, written for the people who have to sign off.

Briefs

Three documents your security team will ask for anyway.

Written for the people who have to sign off, not for a mailing list. Give us a name and a work email and the file is yours.

  • Written for: A CISO or security architect

    Security and architecture brief

    Tenant isolation, permission-aware retrieval, read-only data access, untrusted-content handling, the audit trail, and sandboxing.

  • Written for: A DPO, legal or compliance

    PDPL and residency brief

    Saudi PDPL alignment, CST RS10, where data sits, the on-premises option, retention, and the no-training commitment.

  • Written for: Procurement and risk

    Control mapping summary

    SOC 2 trust services criteria and ISO 27001:2022 Annex A control mapping. nuhaa.ai is not certified under either, and the document says so in the same words this site does.

The questions these documents raise are the ones worth spending a session on.