Security
These are the controls that exist today, described plainly. We list what is in place so you can ask us about each item, and we list what we do not claim.
This document is a draft pending legal review.
Access and isolation
- Each organization's data is isolated from every other organization's.
- Authorization is checked on the server for every request. The browser is never trusted to say who you are or which organization you belong to.
- Role-based access within an organization decides who can view, manage, review and see payment status.
- Privileged actions are written to an audit log.
Accounts and sessions
- Passwords are stored hashed.
- Sessions use secure cookies.
- Sign-in, sign-up, AI features and public forms are rate limited.
Data in transit and in storage
- Traffic is encrypted in transit over HTTPS, with HSTS enabled.
- Uploaded files are stored privately and served only after an authorization check.
- The database is a managed PostgreSQL service, and backups are handled by the hosting provider.
Application
- Inputs are validated on the server, and uploads are checked for type and size.
- Security headers are set, including a content security policy and frame protection.
- Cross-origin submissions to server actions are rejected.
Privacy controls
- Analytics are first-party. There are no third-party trackers.
- Signed-in users can request an export, a correction or deletion of their data from Settings. Requests are handled by platform staff.
Payments and AI
- The platform does not hold client funds. The platform fee can be paid online through a licensed payment gateway's hosted checkout.
- AI features process only the brief and campaign text that a user submits to them, through an optional model provider. Every AI output is a recommendation that a person approves.
Where data is hosted
Data is hosted with cloud providers outside Saudi Arabia at launch. The processors we use are listed in the privacy notice.
What we do not claim
- Compliance with the Saudi Personal Data Protection Law or any other data protection law.
- Any licence, registration or approval from a regulator, including the Communications, Space and Technology Commission.
- SOC 2, ISO 27001 or any other security certification.
- Saudi data residency.
- Integration with Nafath, Mawthooq or any other government or official system. Verification states are tracked and reviewed by platform staff.
Report a vulnerability
If you believe you have found a security problem, tell us before you tell anyone else and give us enough detail to reproduce it. Please do not access other people's data while testing.
Use the contact form and choose the security topic.