Website and product status
A public website over HTTPS
The public website presents the vision and an illustrative prototype. HTTPS on the website does not establish that a product environment is ready to host organizational data.
Fictional demo data
Demo data illustrates the proposed workflow. Do not upload sensitive organizational documents or customer data to the prototype, or include confidential information in contact messages.
Operational product controls
The backend, authentication, tenant isolation, security and privacy controls, and continuity plans require implementation and testing before an actual institutional pilot.
Product design requirements
Data Privacy
Define processing purposes, roles and necessary data; minimize collection; set retention and deletion rules; and assess each organization and sector's requirements before processing begins.
Information Security
Design infrastructure and application controls, manage vulnerabilities, updates, secrets and vendors, and test controls against risk before commercial operation.
Role-Based Access
Apply role-based permissions and least privilege, separate each organization's data, test tenant isolation, and review access and sensitive privileges.
Encryption
Encrypt data in transit and at rest, manage keys appropriately for the deployment environment, and limit service access to data according to organizational needs.
Auditability
Record access, changes, reviews, approvals and execution, linking each event to its actor, time and version while protecting log integrity.
Human Oversight
Define when a review or approval is required before accepting an output or executing an action. Decisions and accountability remain with the authorized person.
Data Residency
Hosting in Saudi Arabia is a target subject to provider verification and organizational and sector requirements. No operational environment or data-processing arrangements have been finalized. Assessment will cover backups, model providers and any data transfers.
Business Continuity
Provide backup, recovery testing, incident response and disaster recovery plans. Recovery and availability objectives will be defined after service needs and risks are assessed.
Responsible AI
Manage model, source and output risks; explain usage limits; test unreliable outputs; and define accountability, challenge and correction processes.
Verification before operation
Before an actual data pilot
Complete authentication, access control, tenant isolation, document management, audit logs, encryption, backup and monitoring. Define processing responsibilities and obtain authorization for data use.
Before commercial launch
Conduct penetration testing, assess security and privacy controls, test recovery and incident response, and review data, AI, cloud and vendor governance.
During operation
Review risks, access and updates; monitor the service; test continuity plans; and address findings and output errors under clearly assigned responsibilities.
Claims need evidence
These principles do not establish compliance with a regulatory framework or standard, or represent certification, a test report or an availability guarantee. Applicable Saudi and sector requirements will be reviewed with specialists, with implementation status and relevant evidence provided before operational commitments.
Organizations can discuss data classification, hosting, access and review requirements during initial validation. Please do not send sensitive information through the contact form.
Explore Responsible AI