YUHINA

Security and vulnerability disclosure

How to report a vulnerability, and what we promise in return.

Last updated: 5 September 2026

Status: pre-release alpha. YUHINA is not generally available. The interface and the generated outputs are in English and Arabic. New accounts receive a small grant of trial credits; there are no paid plans, no subscriptions and no credit packs on sale yet. Features may change or be withdrawn, and generation may fail or be interrupted.

Who operates YUHINA

YUHINA (“YUHINA”, “the service”, “we”) is operated by YUHINA. Full operator details — the registered legal entity, its address, its registration numbers and the governing law of these documents — will be published on this page before any paid plan is offered. Until then, the service is provided as a pre-release alpha and no purchase is possible.

Contact for anything on this page: support-yuhina@magpie.sa.

Reporting a vulnerability

Email support-yuhina@magpie.sa. The machine-readable version of this policy is published at /.well-known/security.txt in line with RFC 9116.

A report is most useful when it contains:

  • what the issue is and what an attacker could do with it;
  • the exact steps to reproduce it, with URLs, requests and timestamps;
  • the account or workspace you were testing with;
  • anything you saw that you should not have been able to see — described, not attached.

What we will do

  • Acknowledge your report within five working days.
  • Tell you our assessment of the severity, and keep you updated while we fix it.
  • Credit you publicly when the fix ships, if you want that.
  • Tell affected customers and the relevant authority without undue delay if the issue exposed their data.

We are a small team in pre-release alpha and we do not yet run a 24/7 on-call rotation, so we will not promise a response time we cannot meet. Five working days is a target we can actually hold to.

Safe harbour

If you make a good-faith effort to follow this policy while researching a vulnerability, we will not pursue or support legal action against you, and we will treat your research as authorised under any applicable computer-misuse law. If a third party brings action against you for work that followed this policy, we will make that authorisation clear. If you are unsure whether something is in scope, ask first at support-yuhina@magpie.sa.

Rules of engagement

  • Test only against accounts and workspaces you created yourself.
  • Stop as soon as you have confirmed a vulnerability. Do not read, copy, alter or keep another person's data, and do not go further into the system than the proof requires.
  • No denial-of-service, load or stress testing, and no spam or high-volume automated scanning.
  • No social engineering, phishing or physical attacks against our people, our providers, or their staff.
  • Do not publish the issue until we have fixed it or 90 days have passed, whichever comes first — and talk to us if you think that window is wrong for a particular issue.
  • Follow the law where you are.

Scope

  • In scope: the YUHINA application and its API, the generation engine, and the marketing website.
  • Out of scope: our providers' own systems (report those to the provider), third-party services we merely link to, and findings that are only a missing best-practice header with no demonstrated impact.
  • Also out of scope: reports produced purely by an automated scanner with no working proof of exploitability, and social-engineering findings about our staff.

No bounty

We do not pay for vulnerability reports. There is no bug bounty programme and none is promised. We are saying so plainly so that no researcher spends time here expecting one. Credit, a fast fix, and a straight answer are what we can offer today.

How the product is built

For context on what you are testing: tenant isolation is enforced at two layers — the application authorises every request, and the database independently enforces the same workspace boundary, so an application bug alone should not cross it. The credit ledger is append-only. An independent paid penetration test is a requirement before public launch and has not yet been carried out.

About this document

These documents are drafted by the YUHINA team and have not yet been reviewed by external counsel. They describe what the product does today. They will be reviewed, and may change materially, before any paid plan is offered.

الأمان والإفصاح عن الثغرات

كيف تُبلِّغ عن ثغرة، وما الذي نلتزم به في المقابل.

آخر تحديث: ٥ سبتمبر ٢٠٢٦

الحالة: إصدار تجريبي مبكر (ألفا). خدمة YUHINA ليست متاحة للعموم بعد. وتتوفَّر الواجهة والمخرجات المُولَّدة باللغتين الإنجليزية والعربية. ويحصل كل حساب جديد على رصيد تجريبي محدود؛ ولا توجد حتى الآن خطط مدفوعة ولا اشتراكات ولا حزم أرصدة معروضة للبيع. وقد تتغيَّر الميزات أو تُسحَب، وقد يفشل التوليد أو ينقطع.

مَن يُشغِّل YUHINA

يُشغِّل خدمة YUHINA («الخدمة»، «نحن») YUHINA. وسوف تُنشَر بيانات المُشغِّل الكاملة — الكيان القانوني المُسجَّل وعنوانه وأرقام تسجيله والقانون الواجب التطبيق على هذه الوثائق — في هذه الصفحة قبل طرح أي خطة مدفوعة. وإلى حين ذلك تُقدَّم الخدمة بوصفها إصدارًا تجريبيًا مبكرًا (ألفا)، ولا يمكن إجراء أي عملية شراء.

للتواصل بشأن أي مما ورد في هذه الصفحة: support-yuhina@magpie.sa.

الإبلاغ عن ثغرة

راسلنا على support-yuhina@magpie.sa. وتُنشَر النسخة القابلة للقراءة آليًا من هذه السياسة على /.well-known/security.txt وفق المعيار RFC 9116.

ويكون البلاغ أنفع ما يكون حين يتضمَّن:

  • ماهية الثغرة وما يمكن للمهاجم فعله بها؛
  • خطوات إعادة إنتاجها بدقة، مع الروابط والطلبات والأوقات؛
  • الحساب أو مساحة العمل التي أجريت الاختبار عليها؛
  • أي شيء اطَّلعت عليه ولم يكن ينبغي أن تراه — موصوفًا لا مُرفَقًا.

ما سنفعله

  • الإفادة باستلام بلاغك خلال خمسة أيام عمل.
  • إبلاغك بتقديرنا لخطورة الثغرة، وإطلاعك أولًا بأول أثناء المعالجة.
  • ذِكر اسمك علنًا عند إصدار الإصلاح، إن رغبت في ذلك.
  • إبلاغ العملاء المتأثرين والجهة المختصة دون تأخير لا مبرر له إذا كشفت الثغرة بياناتهم.

نحن فريق صغير في مرحلة تجريبية مبكرة، ولا نُشغِّل بعدُ مناوبة على مدار الساعة، ولن نَعِد بزمن استجابة لا نستطيع الوفاء به. وخمسة أيام عمل هدف نقدر على الالتزام به فعلًا.

الحماية القانونية للباحث

إذا بذلت جهدًا بحسن نية في اتباع هذه السياسة أثناء بحثك عن ثغرة، فإننا لن نُلاحقك قضائيًا ولن نُساند أي إجراء قانوني ضدك، وسنعُدّ بحثك مأذونًا به بموجب أي نظام سارٍ لإساءة استخدام الأنظمة الحاسوبية. وإذا أقام طرف ثالث دعوى عليك بسبب عمل اتَّبع هذه السياسة، فسنُوضِّح هذا الإذن. وإذا شككت في كون أمر ما داخل النطاق فاسأل أولًا على support-yuhina@magpie.sa.

قواعد الاختبار

  • اختبر فقط على حسابات ومساحات عمل أنشأتها بنفسك.
  • توقَّف فور تأكُّدك من وجود الثغرة. ولا تقرأ بيانات شخص آخر ولا تنسخها ولا تُعدِّلها ولا تحتفظ بها، ولا تتوغَّل في النظام أبعد مما يقتضيه الإثبات.
  • ممنوع اختبار حجب الخدمة أو اختبارات الحمل والإجهاد، وممنوع الإغراق أو الفحص الآلي كثيف الطلبات.
  • ممنوعة الهندسة الاجتماعية والتصيُّد والهجمات المادية على منسوبينا أو مزوِّدينا أو موظفيهم.
  • لا تنشر الثغرة حتى نُصلحها أو تمضي تسعون يومًا، أيهما أسبق — وحدِّثنا إن رأيت أن هذه المهلة غير مناسبة لثغرة بعينها.
  • والتزم بالقانون الساري في مكانك.

النطاق

  • داخل النطاق: تطبيق YUHINA وواجهته البرمجية، ومحرِّك التوليد، والموقع التعريفي.
  • خارج النطاق: أنظمة مزوِّدينا ذاتها (تُبلَّغ للمزوِّد مباشرة)، وخدمات الأطراف الثالثة التي نكتفي بالربط إليها، والملاحظات التي تقتصر على غياب ترويسة من أفضل الممارسات دون أثر مُثبَت.
  • وخارج النطاق كذلك: البلاغات الناتجة عن ماسح آلي بحت دون إثبات عملي لقابلية الاستغلال، وملاحظات الهندسة الاجتماعية المتعلقة بمنسوبينا.

لا توجد مكافآت

لا ندفع مقابل بلاغات الثغرات. فلا يوجد برنامج مكافآت ولا وعد بوجوده. ونقول ذلك صراحةً لئلا يُنفق أي باحث وقته هنا متوقِّعًا مكافأة. وما نقدر على تقديمه اليوم هو ذِكر الفضل وإصلاح سريع وإجابة صريحة.

كيف بُني المنتج

للسياق حول ما تختبره: عزل المستأجرين مفروض على طبقتين — يُصرِّح التطبيق بكل طلب، وتفرض قاعدة البيانات حدَّ مساحة العمل نفسه على نحو مستقل، فلا ينبغي أن يكفي خلل في التطبيق لتجاوزه. وسجل الأرصدة إضافي فقط لا يُعدَّل. واختبار الاختراق المدفوع المستقل شرط لازم قبل الإطلاق العام ولم يُجرَ بعد.

عن هذه الوثيقة

أعدَّ فريق YUHINA هذه الوثائق، ولم تُراجَع بعدُ من مستشار قانوني خارجي. وهي تصف ما تفعله الخدمة اليوم. وستخضع للمراجعة وقد تتغيَّر تغيُّرًا جوهريًا قبل طرح أي خطة مدفوعة.