Skip to content

Security and data protection

What we do with your data, in plain terms, before you ask.

What we do

Eight commitments, each one specific enough that you could hold us to it.

  • Where your data lives

    Your account, your documents and your conversations are stored in the region named in your agreement, and we tell you before that changes. Inference is a separate question: model providers run in their own regions, which provider handles what is set out in the data processing agreement, and no document is sent to one that has not been named there.

  • Encrypted in transit and at rest

    TLS 1.2 or better on every connection, AES-256 on everything stored. Credentials are hashed, never encrypted — there is no key that turns them back into passwords.

  • Who can reach it

    Production access is limited to the engineers who need it, granted for the work in front of them rather than held permanently, and every route to it is behind multi-factor authentication. Inside your workspace, what a member can see is decided by the role you gave them.

  • Separated by workspace

    Every query is scoped to the workspace that issued it at the query layer, not by a filter in application code that someone could forget to apply.

  • Your content is not training data

    Documents, questions and answers belong to your workspace. They are not used to train models, ours or anyone else's, and they are not shared between accounts.

  • You can delete it

    Delete a document, a conversation or the whole account. Deletion removes the content from live systems immediately and from backups on their normal rotation.

  • Access is logged

    Every administrative action against your data is recorded with who, what and when, and the log is visible to your workspace owner.

  • Sub-processors are named

    The model providers and infrastructure we rely on are listed in the data processing agreement, and we tell you before that list changes.

The documents behind this

Everything above is a summary. The commitments that bind us are in the agreements, and they are published rather than sent on request.

Found something?

Report a vulnerability to security@najemai.ae. We acknowledge within one business day and we will not pursue anyone who reports in good faith.

Questions

Common questions

If yours is not here, ask us directly.

Do you train on our data?

No. Conversations, uploaded documents and council sessions belong to your account and are never used to train or fine-tune a model, ours or a provider's.

Who inside our organisation can see what?

Seats are individual. A member sees their own conversations and documents unless they are explicitly shared, and an administrator can see the account's usage without reading its contents.

Where is the data stored?

Data residency is part of the enterprise conversation rather than a fixed answer, because the right answer depends on which regulator you report to. It is agreed in writing before deployment.

Do you support single sign-on?

Yes, on the Enterprise tier, alongside contractual service levels and a security review run with your own team before anything is signed.

Can we delete everything?

Yes. Deleting your account removes your conversations, documents and sessions. Anything already exported is yours and stays with you.

Put the council to work

Create an account and ask your first question in under a minute.

Najem AI produces analysis and drafts for internal use. It is not legal, tax, audit or investment advice and does not create a professional relationship.

Back to top