Security at the heart of our innovation

At IyedeX, security is not just a feature, but a fundamental layer embedded in the very core of our product lifecycle, our infrastructure, and our artificial intelligence systems. We rigorously apply "Secure by Design" and "Privacy by Default" principles as non-negotiable imperatives guiding every architectural decision, model development process, and daily operational practice. Our assistant 3amAli is designed with robust guardrails to protect users in the real Tunisian context, while offering a scalable and resilient platform capable of meeting the strictest security requirements of enterprises and institutions.

Our Principles

1. Privacy

We apply a strict data minimization policy, reinforced by granular access controls and systematic encryption. Private conversations and personal information are never used to train our algorithms without explicit and informed consent, as we consider privacy protection an absolute ethical and technical responsibility.

2. Integrity

The reliability of our systems relies on controlled deployment processes, rigorous version management, and continuous verification mechanisms. Every modification, whether concerning our AI models or our infrastructure, is subject to in-depth reviews to preserve consistency, traceability, and overall service stability.

3. Transparency

We are committed to responsible and clear communication, both in our internal documentation and towards our users. In the event of a security incident, IyedeX prioritizes the rapid sharing of factual and accurate information, avoiding unnecessary speculation, and commits to continuous improvement through rigorous post-incident analyses.

What we protect

Infrastructure

We operate on strictly segmented environments, physically and logically isolating production, staging, and development. Our network architecture benefits from continuous monitoring, strong encryption of data at rest and in transit, as well as proven redundancy and disaster recovery strategies, guaranteeing maximum availability and resilience.

Artificial Intelligence

3amAli's security relies on advanced guardrails designed to prevent abuse, mitigate prompt injection risks, and filter inappropriate content. We integrate sensitivity to the Tunisian cultural context to ensure relevant ethical alignment, with controlled model updates and human supervision for sensitive scenarios.

User Data

Access to sensitive data is governed by the principle of least privilege, granted only upon absolute necessity and for a limited duration. Every access is subject to audited logging and regular reviews. We apply strict retention policies and clear governance rules to preserve our users' trust.

Compliance & Legal Framework

IyedeX operates in strict compliance with Tunisian legislation regarding personal data protection, notably organic law n°2004-63, and adopts a declarative and transparent approach with the National Authority for Protection of Personal Data (INPDP), considering compliance not as a simple administrative formality, but as a continuous operational commitment integrated into our internal governance and data processing workflows, to establish a lasting climate of trust with our users and institutional partners.

INPDP

API Security & Developers

For our partners and developers integrating our technologies, we have implemented an enterprise-grade API security infrastructure. Access to our services is strictly controlled by isolated API keys, subject to granular rate limiting and rigorous validation of every incoming request. Our anomaly detection systems monitor usage patterns in real-time to instantly identify and block any suspicious or malicious activity. This defensive architecture ensures the availability and performance of our critical services, even under high load, ensuring business continuity for our entire ecosystem.

Vulnerabilities

IyedeX firmly believes in responsible disclosure and the invaluable value of collaboration with the international security research community. We encourage researchers to report any potential vulnerability to us in a coordinated manner.

Reporting

To report a vulnerability, please send a detailed report to our dedicated security team. We ask you to include clear proofs of concept, precise reproduction steps, as well as an estimation of the potential impact, via secure channels.

Analysis

Upon receipt, each report undergoes immediate internal triage, followed by an in-depth impact assessment. We commit to acknowledging receipt quickly and conducting a rigorous investigation, aiming for an initial analysis timeframe of 48 business hours.

Resolution

After validation, we proceed with the development and deployment of necessary fixes. Although we do not offer financial rewards, we are happy to publicly recognize significant contributions in our "Hall of Fame".

Contact

For any security-related questions or to report an issue
contact@iyedex.tn