How we handle your data.

We’re a Dubai-licensed FZCO building software and AI for clients across the UAE, GCC, UK, and EU. This page is a plain-text overview of our privacy and security posture. For deeper questions, email info@codenovai.com.

Where data lives

Deployment topology — cloud, on-premise, or sovereign-cloud — is decided per engagement based on the data classes involved and the client’s residency requirements. The specific region and infrastructure are documented in each engagement’s Statement of Work.

Data protection

We do not hold formal compliance certifications today and we don’t represent ourselves as having any. For each engagement we agree the applicable obligations in writing (DPAs, NDAs, retention, encryption, access controls), aligned to the laws the client operates under and the contractual terms of the engagement.

Security baseline

Encryption at rest and in transit, role-based access for client systems we operate, SSO integration where the client’s identity provider supports it, and least-privilege access by default. We do not maintain shared admin credentials across engagements.

AI tooling and sub-processors

When we route requests to third-party AI providers (Anthropic, OpenAI, Google) on behalf of a client, that routing is disclosed and contracted before deployment. Clients with sovereignty requirements can opt for open-weight models on the client’s own infrastructure — this is the default for our Private AI engagements.

Reporting a security concern

Email info@codenovai.com with subject line “Security”. We acknowledge within one business day.

Have a specific privacy or security question?

We answer customer security questions directly under NDA. Get in touch and we’ll respond fast.