Security
An overview of how Abbu protects your organisation's data, written as an honest snapshot of our security approach rather than a binding guarantee.
Last updated 17 June 2026
Our Commitment to Security
Security is central to how we build Abbu. Because teams trust us with their organisation's documents, conversations, and account information, we work to protect that data with care and to be straightforward about how we do it.
This page is a plain-language overview of our security approach. It describes the measures we aim to apply and is not a binding guarantee of any specific outcome. Abbu is an early product, and this is an initial version of our security overview that we expect to update and expand as the product matures.
Hosting and Data Residency in Saudi Arabia
Abbu is hosted in the Kingdom of Saudi Arabia, and we aim to keep customer data resident within the Kingdom. This supports organisations that prefer or are required to keep their data in-country.
Our handling of personal data is guided by the Saudi Personal Data Protection Law (PDPL). As our product and infrastructure evolve, we will continue to align our practices with applicable Saudi data protection requirements.
Per-Organisation Isolation
Abbu is multi-tenant, and each customer organisation's data is logically separated from every other organisation's data. Our systems are designed so that one customer cannot access, view, or query another customer's documents, conversations, or account information.
This isolation also shapes how Abbu answers questions: when a member asks something, Abbu draws only on that organisation's own content and not on the data of any other customer.
Encryption
We use industry-standard encryption to protect data both in transit and at rest. Data moving between users and Abbu is protected using encrypted connections, and data stored in our systems is encrypted using widely accepted methods.
Encryption is designed to reduce the risk that data can be read if it is intercepted or if storage media are accessed without authorisation.
Access Controls and Authentication
Access to organisation data is controlled. Members use Abbu through their own accounts, and organisation admins manage their team through the web admin dashboard.
Internally, we follow the principle of least privilege: our team members are granted only the access they need to operate and support the service. Access to production systems and customer data is restricted, authenticated, and intended to be used only when necessary.
Infrastructure and Network Security
Abbu runs on managed cloud infrastructure, and we rely on a combination of platform and application-level controls to protect our systems. At a high level, we aim to limit the exposure of internal services, separate our environments, and keep our systems updated with security patches.
We design our network boundaries so that only the necessary services are reachable, and we work to reduce the attack surface of the components that handle customer data.
Monitoring and Logging
We maintain logging and monitoring across key parts of our infrastructure to help us detect unusual or unauthorised activity and to support investigation if something goes wrong.
These logs also help us operate the service reliably and respond to issues promptly.
Backups and Resilience
We take backups of important data so that we can aim to recover in the event of data loss or a service disruption, and our goal is to keep Abbu available and to restore service and data when needed.
We continue to invest in the resilience of our systems, and our backup and recovery practices will mature alongside the product.
AI Accuracy and Citing Sources
Abbu answers questions and drafts paperwork using artificial intelligence. To help you check its work, Abbu is designed to cite its sources, pointing each answer back to the document or section in your organisation's own content that it relied on.
Citations are intended to reduce errors and make answers easier to verify, but AI can still make mistakes or produce incomplete or inaccurate output. Abbu is a tool to assist your team, not a substitute for professional, legal, or other expert advice. You are responsible for reviewing Abbu's output and confirming its accuracy and suitability before relying on or acting on it.
Third-Party Service Providers
Abbu relies on a small number of trusted third-party providers to deliver the service. These include cloud and hosting infrastructure, large-language-model providers that power Abbu's drafting and question-answering, and the messaging platform (Telegram) where many teams use Abbu day to day.
We aim to work with providers that maintain appropriate security practices and to share only the data needed for them to perform their function. We expect our use of these providers to evolve, and we will update this overview as it does.
Responsible Disclosure
We welcome reports from the security research community. If you believe you have found a security vulnerability or other security issue in Abbu, please contact us at basil@abbu.io with enough detail for us to reproduce and investigate it.
We ask that researchers give us a reasonable opportunity to investigate and address an issue before disclosing it publicly, and that testing avoids accessing, modifying, or deleting data that is not your own. We appreciate good-faith efforts that help us keep Abbu safe.
Governing Law
This security overview, and our handling of the data described here, are governed by the laws of the Kingdom of Saudi Arabia, including the Saudi Personal Data Protection Law (PDPL) where applicable.
An Honest Note on Limitations
No system, product, or organisation can be perfectly secure, and we do not claim that Abbu is. We work to apply sensible, industry-standard measures and to reduce risk, but no method of transmission or storage is completely secure.
As an early-stage product, our security practices will continue to mature as Abbu grows. This is an initial version of our security overview and may be updated over time. If you have questions about the security of Abbu, please reach out to us at basil@abbu.io.