Security
Last updated: 7 September 2026
This page describes security at the company level: how the oai.sa website is run and how to report a vulnerability to us. The security of the Rushd platform itself is documented separately on the Rushd Security page.
1. The company website
oai.sa is an informational site served over TLS from cloud infrastructure in Saudi Arabia. It has no user accounts and holds no case or client data. The only personal information that passes through it is what a visitor chooses to send via the contact form, and the only records it keeps in your browser are a language preference, a theme preference, your answer to the analytics banner, and a short-lived rate-limit entry for that form. There are no advertising cookies; Google Analytics 4 runs only if you allow it in the banner, as the Cookie Policy describes.
2. The Rushd platform
Product security is documented with the product. The Rushd Security page sets out the platform's infrastructure, encryption, access controls, audit logging and the rules governing staff access to customer data; firms evaluating Rushd should rely on that page.
3. Reporting a vulnerability
If you believe you have found a security flaw in the website, in Rushd or in any system we operate, write to info@oai.sa with enough detail for us to reproduce the issue. Reports of this kind are read outside our normal support hours as well as during them.
4. Good-faith research
We do not take legal action against security research conducted in good faith. Three conditions apply: do not access, alter or delete data that is not yours; do not degrade or disrupt the service for others; and give us reasonable time to fix the issue before disclosing it publicly. Testing that goes beyond these limits is not research — it is prohibited by our Acceptable Use Policy.