AQLERARequest a DemoAR
AQLERA

Trust starts with clarity about what is available and what is planned.

Security, privacy and accountability are foundational requirements for the proposed product. This page explains the design direction and capability status without claiming completed product controls or certification.

Website and product status

Available Now

A public website over HTTPS

The public website presents the vision and an illustrative prototype. HTTPS on the website does not establish that a product environment is ready to host organizational data.

Prototype

Fictional demo data

Demo data illustrates the proposed workflow. Do not upload sensitive organizational documents or customer data to the prototype, or include confidential information in contact messages.

Roadmap

Operational product controls

The backend, authentication, tenant isolation, security and privacy controls, and continuity plans require implementation and testing before an actual institutional pilot.

Product design requirements

Planned

Data Privacy

Define processing purposes, roles and necessary data; minimize collection; set retention and deletion rules; and assess each organization and sector's requirements before processing begins.

Planned

Information Security

Design infrastructure and application controls, manage vulnerabilities, updates, secrets and vendors, and test controls against risk before commercial operation.

Planned

Role-Based Access

Apply role-based permissions and least privilege, separate each organization's data, test tenant isolation, and review access and sensitive privileges.

Planned

Encryption

Encrypt data in transit and at rest, manage keys appropriately for the deployment environment, and limit service access to data according to organizational needs.

Planned

Auditability

Record access, changes, reviews, approvals and execution, linking each event to its actor, time and version while protecting log integrity.

Planned

Human Oversight

Define when a review or approval is required before accepting an output or executing an action. Decisions and accountability remain with the authorized person.

Planned

Data Residency

Hosting in Saudi Arabia is a target subject to provider verification and organizational and sector requirements. No operational environment or data-processing arrangements have been finalized. Assessment will cover backups, model providers and any data transfers.

Planned

Business Continuity

Provide backup, recovery testing, incident response and disaster recovery plans. Recovery and availability objectives will be defined after service needs and risks are assessed.

Planned

Responsible AI

Manage model, source and output risks; explain usage limits; test unreliable outputs; and define accountability, challenge and correction processes.

Verification before operation

  1. Before an actual data pilot

    Complete authentication, access control, tenant isolation, document management, audit logs, encryption, backup and monitoring. Define processing responsibilities and obtain authorization for data use.

  2. Before commercial launch

    Conduct penetration testing, assess security and privacy controls, test recovery and incident response, and review data, AI, cloud and vendor governance.

  3. During operation

    Review risks, access and updates; monitor the service; test continuity plans; and address findings and output errors under clearly assigned responsibilities.

Claims need evidence

These principles do not establish compliance with a regulatory framework or standard, or represent certification, a test report or an availability guarantee. Applicable Saudi and sector requirements will be reviewed with specialists, with implementation status and relevant evidence provided before operational commitments.

Organizations can discuss data classification, hosting, access and review requirements during initial validation. Please do not send sensitive information through the contact form.

Explore Responsible AI