Rushd

Security

Last updated: 7 September 2026

Rushd holds case files, client records, and privileged correspondence. This page states plainly what protects that data today, where it lives, and how to report a vulnerability.

1. Scope of This Page

This page covers the Rushd platform: the web application at rushd.oai.sa, the client portal, and the Rushd mobile app (together, the "Platform"). It describes measures that exist now, not aspirations. Where a common assurance is absent — a certification, a contractual uptime commitment — we say so rather than imply otherwise.

2. Hosting and Data Residency

The Platform runs on Saudi-based cloud infrastructure. Production compute, the database, and file storage are hosted inside the Kingdom of Saudi Arabia.

Three exceptions apply. AI drafting and assistant features use large language models from a third-party AI provider, and those AI requests may be processed by that provider in regions outside the Kingdom. Customer content is not used to train AI models without the customer's explicit consent. Transactional email — invoices, reminders, notices — is delivered through a third-party email service that processes data in the United States, and mobile push notifications are delivered through Apple's and Google's services outside the Kingdom; the Privacy Policy and the PDPL page describe both.

3. Encryption

Traffic between your device and the Platform is encrypted with TLS. Data stored on our cloud infrastructure — the database and uploaded files — is encrypted at rest.

4. Access Control and Authentication

Each Firm controls who sees what. Access inside a Firm follows role-based access control with per-role permissions, so a User sees only what their role allows. Multi-factor authentication is available for every account, and a Firm can restrict logins to an approved list of IP addresses. Administrators can review login history and revoke any active session.

5. Monitoring and Abuse Prevention

An audit log visible to the Firm's administrators records who did what and when. Rate limiting and automatic login lockout slow down credential-guessing attacks. In production we run our own error monitoring on the same Saudi-based infrastructure to catch faults early; no third-party monitoring service receives customer data, and the mobile app contains no analytics or crash-reporting SDK.

6. Payment Security

Card payments run through our Saudi-based payment processor's hosted payment form. Your card number goes to the processor, not to us; O AI servers never receive or store card data.

7. Staff Access

Our staff can reach customer data only where their work requires it, and that access is limited and logged.

8. Availability

We work to keep the Platform available, but we do not currently offer a contractual service-level agreement or uptime guarantee. When an incident affects your Firm, we notify you by email.

9. Incident Response and Breach Notice

If a personal data breach occurs, we notify the Saudi Data & AI Authority (SDAIA) within 72 hours where the law requires it, and we inform affected Firms without undue delay, together with the individuals whose data we control ourselves; for client and case data, the Firm, as controller, notifies its own clients, and we give it what it needs to do so. The notice describes what happened, what data was involved, and what we are doing about it.

10. Reporting a Vulnerability

Security researchers who find a flaw in the Platform should write to info@oai.sa. Reports sent to that address are read outside normal support hours.

We ask three things: do not access data that is not yours, do not disrupt the service, and give us reasonable time to fix the issue before any public disclosure. Research conducted in good faith within those limits will not face legal action from us. Testing outside these rules — vulnerability scanning or penetration testing against live systems without permission — is prohibited under our Acceptable Use Policy.

11. Changes to This Page

We revise this page as our practices evolve and publish each revision with its date. Material changes are announced by email or in the Platform, normally 30 days before they take effect.

12. Contact

For anything security-related — questions about this page, vulnerability reports, or concerns about your Firm's data — write to info@oai.sa.