Naateq
  1. Home
  2. Security and compliance

Your customers’ conversations never leave your server

Most tools send your customers’ conversations to foreign servers. Naateq runs on your side — and that is a regulatory difference, not a technical detail.

Why this now matters

The Personal Data Protection Law is in force, and the grace period has ended

The Saudi Personal Data Protection Law has been in force since 14 September 2023, and the compliance grace period ended on 14 September 2024, and it restricts transferring residents’ data outside the Kingdom. Committees at the Saudi Data and AI Authority do issue fines and operational suspensions in practice.

When you send your customers’ conversations to a foreign platform, you are transferring personal data outside the Kingdom — whether you realised it or not.

The difference in practice

  • A foreign cloud tool: the conversation text leaves your device, is stored abroad, and may be used for training.
  • Naateq on-premise: the model runs on your server. Nothing leaves.
Guarantees

What we actually commit to

Full on-premise operation

The language model runs on your own server. No keys to an external provider, no copy of your conversations on our side, and no use of your data to train any model.

Disclosure written in code

It announces that it is an automated assistant in the first conversation, and offers to connect you to a human in the same line — and both are a line in the code, not an instruction in the prompt that the model can ignore. Observed live: the model ignored the instruction and replied without disclosing, so disclosure was moved from the prompt into the code and has not failed since. This is also what SDAIA’s generative AI guidance directs.

A guard against prompt injection

Every incoming text is screened before it reaches the model. Requests that try to override instructions, impersonate the owner or extract the prompt are blocked before processing — because the model reads instructions and data on one channel and cannot be hardened with a prompt.

A complete audit log, on your side

Every message, every decision and every document is recorded with its time and its source, in text files inside your own system — readable with any tool, for an internal review or a regulatory request. There is no database of ours to ask for a copy from.

The decisions we do not leave to the model

Anything touching money or law is executed in code. The model only classifies and phrases.

Decisions governed by code, not by the model
DecisionExecuted byWhy
Price calculationCodeA quote is a financial commitment; a model can be confidently wrong.
Project type classificationModel + code validationThe model classifies, and the code rejects a classification that contradicts the evidence.
Customer name and number on the documentCodeOnly what the customer actually said is written — to prevent copying the prompt’s examples.
Sending the contractYouA contract is a legal commitment; it reaches the customer only once you approve it on WhatsApp.
Disclosing that it is automatedCodeA regulatory obligation, not something left to a line of text.
Escalating to a humanCodeLimits you set numerically, not a judgement made in language.

17 deterministic guards in total — each one added after a real gap appeared in operation, not as a theoretical precaution.

Security questions

With the on-premise option: only on your own server, and we hold no copy. With managed operation: on servers in your country — or in the region you choose — and we hand you a full copy whenever you ask. So your customers’ data crosses no border, which is what the Gulf data protection laws require, varied as they are.

No. One customer’s data is never used to train anything serving another customer. And the training log — if you enable it — stays in your system and serves your bot alone.

The input guard blocks the attempt before it reaches the model: overriding instructions, impersonating the owner, extracting the instructions, or evading detection by writing letters as digits. And the block is logged in the dashboard for you to see.

We hold no international certifications yet, and we will not claim what we do not have. What we offer is the on-premise option — which in practice is stronger than a certificate on a foreign server, because the data never leaves your custody in the first place.

Have a specific compliance requirement?

Send it to us before you buy. If we cannot meet it, we will say so.

Get started