Security and vulnerability disclosure
How to report a vulnerability, and what we promise in return.
Last updated: 5 September 2026
Status: pre-release alpha. YUHINA is not generally available. The interface and the generated outputs are in English and Arabic. New accounts receive a small grant of trial credits; there are no paid plans, no subscriptions and no credit packs on sale yet. Features may change or be withdrawn, and generation may fail or be interrupted.
Who operates YUHINA
YUHINA (“YUHINA”, “the service”, “we”) is operated by YUHINA. Full operator details — the registered legal entity, its address, its registration numbers and the governing law of these documents — will be published on this page before any paid plan is offered. Until then, the service is provided as a pre-release alpha and no purchase is possible.
Contact for anything on this page: support-yuhina@magpie.sa.
Reporting a vulnerability
Email support-yuhina@magpie.sa. The machine-readable version of this policy is published at /.well-known/security.txt in line with RFC 9116.
A report is most useful when it contains:
- what the issue is and what an attacker could do with it;
- the exact steps to reproduce it, with URLs, requests and timestamps;
- the account or workspace you were testing with;
- anything you saw that you should not have been able to see — described, not attached.
What we will do
- Acknowledge your report within five working days.
- Tell you our assessment of the severity, and keep you updated while we fix it.
- Credit you publicly when the fix ships, if you want that.
- Tell affected customers and the relevant authority without undue delay if the issue exposed their data.
We are a small team in pre-release alpha and we do not yet run a 24/7 on-call rotation, so we will not promise a response time we cannot meet. Five working days is a target we can actually hold to.
Safe harbour
If you make a good-faith effort to follow this policy while researching a vulnerability, we will not pursue or support legal action against you, and we will treat your research as authorised under any applicable computer-misuse law. If a third party brings action against you for work that followed this policy, we will make that authorisation clear. If you are unsure whether something is in scope, ask first at support-yuhina@magpie.sa.
Rules of engagement
- Test only against accounts and workspaces you created yourself.
- Stop as soon as you have confirmed a vulnerability. Do not read, copy, alter or keep another person's data, and do not go further into the system than the proof requires.
- No denial-of-service, load or stress testing, and no spam or high-volume automated scanning.
- No social engineering, phishing or physical attacks against our people, our providers, or their staff.
- Do not publish the issue until we have fixed it or 90 days have passed, whichever comes first — and talk to us if you think that window is wrong for a particular issue.
- Follow the law where you are.
Scope
- In scope: the YUHINA application and its API, the generation engine, and the marketing website.
- Out of scope: our providers' own systems (report those to the provider), third-party services we merely link to, and findings that are only a missing best-practice header with no demonstrated impact.
- Also out of scope: reports produced purely by an automated scanner with no working proof of exploitability, and social-engineering findings about our staff.
No bounty
We do not pay for vulnerability reports. There is no bug bounty programme and none is promised. We are saying so plainly so that no researcher spends time here expecting one. Credit, a fast fix, and a straight answer are what we can offer today.
How the product is built
For context on what you are testing: tenant isolation is enforced at two layers — the application authorises every request, and the database independently enforces the same workspace boundary, so an application bug alone should not cross it. The credit ledger is append-only. An independent paid penetration test is a requirement before public launch and has not yet been carried out.
About this document
These documents are drafted by the YUHINA team and have not yet been reviewed by external counsel. They describe what the product does today. They will be reviewed, and may change materially, before any paid plan is offered.