Back to SenseCore 360

Security Disclosure & assurance status

Report a concern

Use the existing general contact hani@zednyai.com to request a secure disclosure channel. Send a brief description and affected route; do not email passwords, tokens, health records or full data dumps. A dedicated security mailbox and response SLA remain to be confirmed.

Current safeguards

The shared build uses local script dependencies, organisation/platform query scoping, permission-aware controls, non-persistent Supabase client sessions, defensive export handling and HTTPS security-header configuration. Server-side authorisation must be separately verified for the actual deployment; browser checks alone are insufficient.

Known limitations

Legacy inline handlers still require an unsafe-inline script CSP. Backend policy completeness, subscription enforcement, privileged routes, SSRF/endpoint allowlists and cross-platform access require deployment-specific testing. Recent local checks are not a penetration test.

Framework status

Saudi PDPL obligations and ISO/IEC 27001 controls are assessment targets, not claimed certifications. HIPAA applicability depends on the parties and use case; no HIPAA-equivalent designation is claimed.

Assessment references

Consult the official SDAIA regulations, ISO/IEC 27001 standard description, and HHS covered-entity guidance. An accountable owner must approve the security and legal assessment before production use.

Official references: SDAIA regulations · ISO/IEC 27001 · HHS applicability guidance

هذه وثيقة مراجعة أولية. يجب تأكيد الجهة القانونية وموقع معالجة البيانات وسياسات الاحتفاظ والالتزامات التعاقدية قبل اعتماد النشر. لا تمثل شهادة امتثال أو ضماناً لإقامة البيانات.