Security Disclosure & assurance status
Report a concern
Use the existing general contact hani@zednyai.com to request a secure disclosure channel. Send a brief description and affected route; do not email passwords, tokens, health records or full data dumps. A dedicated security mailbox and response SLA remain to be confirmed.
Current safeguards
The shared build uses local script dependencies, organisation/platform query scoping, permission-aware controls, non-persistent Supabase client sessions, defensive export handling and HTTPS security-header configuration. Server-side authorisation must be separately verified for the actual deployment; browser checks alone are insufficient.
Known limitations
Legacy inline handlers still require an unsafe-inline script CSP. Backend policy completeness, subscription enforcement, privileged routes, SSRF/endpoint allowlists and cross-platform access require deployment-specific testing. Recent local checks are not a penetration test.
Framework status
Saudi PDPL obligations and ISO/IEC 27001 controls are assessment targets, not claimed certifications. HIPAA applicability depends on the parties and use case; no HIPAA-equivalent designation is claimed.
Assessment references
Consult the official SDAIA regulations, ISO/IEC 27001 standard description, and HHS covered-entity guidance. An accountable owner must approve the security and legal assessment before production use.
Official references: SDAIA regulations · ISO/IEC 27001 · HHS applicability guidance
هذه وثيقة مراجعة أولية. يجب تأكيد الجهة القانونية وموقع معالجة البيانات وسياسات الاحتفاظ والالتزامات التعاقدية قبل اعتماد النشر. لا تمثل شهادة امتثال أو ضماناً لإقامة البيانات.