Security Overview
| Field | Value |
|---|---|
| Document ID | NXW-PUB-SECURITY-OVERVIEW |
| Version | 1.0 |
| Issue Date | 2026-01-01 |
| Next Review | 2027-01-01 |
| Owner | Chief Information Security Officer (CISO) |
| Classification | Public |
1. Purpose and Scope
This document provides a high-level overview of the security and compliance posture of Nexwift and the Aram platform. It is intended for prospective and existing customers, partners, and other stakeholders who need assurance that Nexwift operates a controlled, risk-managed service without disclosing internal architecture, sub-processor identities, or other information whose publication could weaken the security of the service.
The scope of this overview covers Aram's text, voice, and video customer-engagement capabilities and the shared platform services that support them. Detailed technical evidence, formal attestations, and control-level documentation are made available to qualified parties under a Non-Disclosure Agreement (NDA) as described in Section 15.
2. Governance and Compliance Framework
Nexwift operates an Information Security Management System (ISMS) whose control set is aligned with:
- ISO/IEC 27001:2022 — Information security management systems.
- Saudi National Cybersecurity Authority Essential Cybersecurity Controls (NCA ECC).
- Saudi Personal Data Protection Law (PDPL) and the implementing regulations issued by the competent Saudi authority.
Ownership of the ISMS sits with the Chief Information Security Officer (CISO). A Data Protection Officer (DPO) is designated for personal-data matters. Policies are reviewed at least annually and after material change to services, threat landscape, or applicable law.
For services delivered through Aram, Nexwift typically acts as a Data Processor on behalf of the customer organisation, which acts as the Data Controller. For its own internal data (employees, prospects, billing, operational telemetry), Nexwift acts as a Data Controller.
3. Data Protection Principles
Nexwift applies the PDPL principles to all personal data processed under a customer engagement:
| Principle | How Applied |
|---|---|
| Lawfulness | Processing carried out only on documented Controller instructions or a documented lawful basis. |
| Purpose limitation | Purposes are specified, explicit, and legitimate, and recorded in the Data Processing Agreement (DPA) or records of processing. |
| Data minimisation | The platform does not request personal identifiers from beneficiaries by default; outbound queries to third-party providers carry only the minimum data required; logging and telemetry exclude personal data by default. |
| Accuracy | Rectification is routed through the customer Controller via the standard data-subject-rights workflow. |
| Storage limitation | Retention periods are defined per data category; customer-specific requirements set in a DPA override the defaults where they require shorter retention. |
| Integrity and confidentiality | Enforced through the technical and organisational measures described in Sections 4 to 8. |
| Accountability | Records of processing, audit logs, and evidence artefacts are maintained. |
Nexwift will acknowledge and respond to data subject requests within the timeframes required by applicable law.
4. Identity, Access, and Administration
- Multi-Factor Authentication (MFA) is mandatory for all administrative access to production systems and to platform management consoles.
- Role-Based Access Control (RBAC) with least-privilege assignments governs access to customer data and platform components.
- A designated production-access role limits the population of personnel who may operate on production systems; access is granted on a documented need-to-know basis and reviewed periodically.
- Administrative sessions are logged and monitored.
5. Logging, Monitoring, and Detection
Application, security, and access events are recorded to tamper-resistant audit logs. Centralised monitoring supports detection of anomalous behaviour, availability events, and policy violations. Alerts are triaged in line with the Incident Management Policy. Retention of audit logs follows the schedule set out in the Data Retention Policy.
6. Vulnerability and Patch Management
Nexwift operates a vulnerability-management programme that includes:
- Recurring scanning of platform components and dependencies.
- Risk-based remediation prioritised by exploitability, exposure, and impact.
- Tracking of remediation to closure, with third-party attestations available under NDA.
- Coordination with sub-processors on vulnerabilities affecting their infrastructure, relying on their independent third-party audit reports where relevant.
Nexwift welcomes good-faith security research; a coordinated-disclosure channel is available through the contact address in Section 17.
7. Incident Management
Security incidents are handled under a documented lifecycle: detection and reporting, triage and classification, containment, eradication, recovery, and post-incident review. A severity ladder (SEV-1 to SEV-4) drives response commitments.
Customer notification: affected customers are notified without undue delay and in any event within 72 hours of confirmation of an incident that meets the notification threshold, in line with each customer's DPA and PDPL Article 19. Notifications include the nature of the incident, categories and approximate volume of data affected, likely consequences, measures taken and proposed, and a contact point. Notification is not an acknowledgement of fault and may be provided in phases where complete information is not yet available, with subsequent information supplied without undue delay as it becomes known, to the extent reasonably known and available at the time.
For personal-data breaches, the customer (as Data Controller) is responsible for notification to the supervisory authority and to data subjects where required. Nexwift provides the information required to support such notification.
Where an incident originates in a sub-processor, Nexwift assesses the impact and notifies affected customers as if the incident had occurred in Nexwift's own systems.
8. Business Continuity and Resilience
Production services are hosted with EU-based cloud infrastructure provider(s) certified against internationally recognised standards. Continuity measures include:
- Geographic separation within the European Union to reduce single-site risk.
- Encrypted backups on a documented rolling window.
- Periodic restore testing to validate recovery procedures.
- Documented recovery objectives per service tier, available under NDA.
Third-party platform outages outside Nexwift's control (for example, messaging channel platform(s), AI inference provider(s), telephony provider(s), and WebRTC/media infrastructure provider(s)) are addressed through the mitigations set out in the Business Continuity Plan. Such outages are excluded from availability commitments, and service credits (where applicable) are the customer's sole financial remedy for availability shortfalls, without prejudice to termination rights for sustained material breach.
9. Secure Development Lifecycle
Nexwift operates a Secure Development Lifecycle covering requirements, design, implementation, testing, release, and post-release monitoring. Controls include source-code review, dependency management, secret scanning, environment segregation between development, staging, and production, and change-management approvals for production deployments.
10. Supplier and Sub-processor Risk
Nexwift operates a Third-Party / Supplier Risk programme. Sub-processors and material suppliers are subject to due diligence covering security posture, applicable certifications, data-protection terms, and continuity. Suppliers are engaged under written agreements imposing obligations substantially equivalent to those Nexwift itself accepts.
Categories of engaged parties include:
- EU-based cloud infrastructure provider(s).
- AI inference provider(s) and managed-embeddings provider(s).
- Messaging channel platform(s) (typically under the customer's own commercial relationship).
- Telephony provider(s) where voice is enabled.
- WebRTC/media infrastructure provider(s) for voice and video sessions.
- Error monitoring provider(s), EU-region-hosted, with personal-data scrubbing applied at source.
Nexwift uses commercially reasonable efforts to impose equivalent data-protection obligations on each sub-processor. For widely-used cloud, AI, and infrastructure providers, Nexwift contracts on the providers' standard published data-processing terms where those terms are recognised as aligned with GDPR/PDPL standards. Nexwift remains liable to the customer for the performance of its sub-processors' data-protection obligations to the extent set out in the Master Agreement.
Sub-processor identities are shared as a categorical list in this public document and by name to customers under the DPA.
11. Personnel Security
- All personnel sign a Non-Disclosure Agreement (NDA) and accept the Acceptable Use Policy (AUP) at onboarding.
- Security-awareness training is delivered at onboarding and refreshed periodically, with additional targeted training for privileged roles.
- Engagement-specific vetting (for example, additional background checks) is available on documented customer requirement and is arranged during onboarding of the relevant personnel.
- Access is revoked upon change of role or separation, under a documented offboarding procedure.
12. AI Safety and Human Oversight
Aram's AI-driven capabilities are governed by an AI Safety and Governance Framework whose control set aligns with the NIST AI Risk Management Framework. Deployed use cases are classified as Informational or Transactional; no agent takes autonomous action in third-party systems beyond sending the configured channel reply.
| Control | Description |
|---|---|
| Agent scope restriction | Each agent operates within a scope defined in its system prompt and configuration; out-of-scope requests are redirected or handed off. |
| Sensitive-topic handling | Configurable redirection for politically or otherwise sensitive topics; no medical, legal, or financial advice is provided. |
| Human hand-off | Every conversation supports transfer to a human operator; the customer dashboard exposes a real-time takeover control. |
| Kill-switch | Customers may disable agent replies for a channel, an agent, or the whole tenant at any time. |
| Audit trail | Inputs, outputs, retrieval references, and guardrail triggers are logged. |
| Pre-publish approval | Replies posted to public channels require staff review and approval before publication unless expressly waived by the customer in writing. |
AI outputs are advisory only and are not a substitute for professional judgement. Voice AI is not an emergency service and must not be used in place of emergency response channels.
13. Text, Voice, and Video Coverage
The controls in this document apply to text, voice, and video interactions handled by the platform.
| Modality | Notes |
|---|---|
| Text | Applies to web chat, messaging channels, and platform APIs. |
| Voice | Real-time audio sessions are protected in transit through the WebRTC/media infrastructure provider(s) and telephony provider(s) used to carry the session. |
| Video | Real-time audio/video sessions follow the same protections as voice. |
End-to-end encryption is preserved where the channel and client stack technically support it. Recording of text, voice, and video sessions and the generation of transcripts and summaries are optional and configurable by the customer per agent, channel, and session type. Where recording is enabled, the customer is responsible for ensuring that beneficiaries are informed and, where applicable law requires, that consent is obtained. Recordings, transcripts, and summaries are treated as customer data (see Section 14).
14. Data Ownership
Customer data — including customer configurations, knowledge-base content, conversation transcripts, recordings, and summaries — remains the property of the customer. Nexwift retains ownership of the Aram platform, its models and configurations, and aggregated telemetry that does not identify a customer or a beneficiary. Nothing in a service relationship transfers ownership of a party's underlying intellectual property to the other party.
Nexwift does not use customer data to train shared or foundation AI models, and contracts with its AI sub-processors on terms that prohibit such training on customer data. Tenant-specific fine-tuning or embedding, where explicitly configured by the customer, remains scoped to that customer's own tenant and is treated as customer data.
15. Evidence Available Under NDA
The following materials are available to qualified parties under a signed NDA:
- ISO/IEC 27001:2022 Statement of Applicability (SoA).
- NCA ECC self-assessment.
- PDPL compliance statement.
- AI Risk Assessment.
- Additional control-level evidence relevant to a specific engagement, on request.
16. Governing Law and Jurisdiction
This document and the relationship between Nexwift and its customers are governed by the laws of the Kingdom of Saudi Arabia. Any dispute or matter arising in connection with the services is subject to the exclusive competence of the competent Saudi courts and authorities.
Vendor-protection defaults apply: liability is capped as set out in the Master Agreement; service credits (where applicable) are the sole financial remedy for availability shortfalls; AI outputs are advisory only; force majeure and third-party outages outside Nexwift's control are excluded; Nexwift acts using commercially reasonable efforts and provides notifications without undue delay (except for the fixed PDPL 72-hour breach-notification window described in Section 7). Nexwift reserves the right to suspend services for Acceptable-Use-Policy violations, non-payment, or an imminent security risk. Nexwift may update these terms from time to time. The current version is always available at this URL. Continued use of the platform after publication constitutes acceptance of the updated terms.
This document is provided for informational purposes only, describes the security posture at the date of issue, and may be updated from time to time. It does not itself create representations, warranties, or contractual commitments beyond those expressly set out in the Master Agreement, DPA, and other executed contract documents between Nexwift and the customer. In the event of any conflict between this document and those executed contract documents, the executed contract documents prevail.
17. Contact
| Purpose | Contact |
|---|---|
| General | info@nexwift.com |
| Data Protection Officer (DPO) | info@nexwift.com (attn: Data Protection Officer) |
| Security research and coordinated disclosure | info@nexwift.com (attn: CISO) |
| Compliance documentation requests | info@nexwift.com (attn: Compliance) |
Nexwift responds to inquiries during business hours and typically outside those hours on a best-effort basis.