Trust & security
We build systems that handle sensitive documents, money and decisions. These are the principles we keep on every project.
Your data stays with you
- We design solutions that can run on the organisation’s own servers, or fully offline when needed, as with Ijam.
- We take Saudi Arabia’s Personal Data Protection Law into account: minimal collection, a defined purpose and set retention periods.
- We do not use client data to train models or for anything outside the project without written consent.
AI agents under human oversight
- Each agent has one clear task and a written playbook that sets what it may and may not do.
- Double review: agent output is checked before execution in sensitive operations.
- Financial limits: anything above the set limit runs only with explicit approval from a responsible person.
- Separation of duties: the agent that negotiates does not pay, and the one that pays does not choose the supplier.
- Full audit trail: every decision is logged with its reason and who made it.
AI that does not make things up
- In knowledge products such as the Legal Library, the agent answers only from approved texts and cites its source.
- When the agent finds no suitable text, it says so instead of guessing.
- Anything AI produces for public release is reviewed by a person first.
System security
- Encrypted connections (HTTPS) across all our systems and sites.
- We are guided by the Essential Cybersecurity Controls of Saudi Arabia’s National Cybersecurity Authority when designing systems.
- Backups and fallbacks for critical tools, with real-time error monitoring.
Report a vulnerability
- If you find a security issue in any of our systems, email info@mubtkrat.com with the details. We handle reports confidentially and respond as soon as possible.