Security & privacy
Reporting a vulnerability
Email dpo@execraai.com with a subject starting SECURITY:, the affected path and minimal reproduction steps. Never send live credentials or other people's data. Official file: https://execlogic.com.sa/.well-known/security.txt.
Published hostnames are identifiers, not authorization to test. Active testing against production requires prior written authorization stating targets, methods and time window.
Controls that exist today
- TLS in transit on every host with HSTS.
- Content Security Policy plus
X-Frame-Options,Referrer-PolicyandPermissions-Policyheaders. - Global and per-route rate limits on authentication and execution.
- Short-lived access tokens, refresh-token rotation, optional two-factor authentication.
- Deterministic redaction of known personal-data patterns before anything reaches a language model, with a best-effort recognition stage on top.
- Hash-chained audit log; self-service data export and account deletion from settings.
What we do not claim
- No PDPL certification and no SOC 2 report.
- No guaranteed in-Kingdom data residency: processing relies on multi-region processors disclosed on the Trust & Compliance page.
- Personal-data redaction is risk reduction, not an absolute guarantee.