Who this is for
Most Linux servers in the UAE are not run by security teams. They are run by the developer who built the product, the agency that built the website, the IT manager who also looks after the laptops, or the hosting provider whose customers expect the server to be safe. The servers hold customer records, orders and payment flows all the same.
SecAI is built for that situation. It does the watching that nobody on a small team has hours for, keeps the list of things that need a person short, and leaves the decisions that carry risk with you.
- Small and mid-sized businesses whose website, store or internal system runs on a Linux VPS or dedicated server.
- Software companies that run their own product on Linux and have no security engineer yet.
- Agencies and freelancers responsible for client servers.
- Hosting providers, managed service providers and resellers who want to offer server security under their own brand.
What UAE organisations are asked to demonstrate
Whether the question comes from a regulator, an enterprise customer's security questionnaire, a cyber insurance form or your own board, it tends to be the same six questions about the servers. Each is something a host agent can observe continuously rather than once a year.
- Access. Who can log in and with what privilege: SSH logins and failures, new accounts, new authorized keys, sudo grants, and privilege changes that happen outside any administrator session.
- Vulnerability management. The packages actually installed on each server, matched against published CVE data every 12 hours, with the fixed version where the advisory names one.
- System changes. Changes to the files that matter, accounts, sudoers, SSH configuration, cron, systemd units and PAM, with the content of the change for the text files where that is safe to keep.
- Monitoring. Processes running from temporary directories, web shell candidates in web roots, new outbound destinations, floods, and resource behaviour against the server's own baseline.
- Incident handling. What was detected, what was blocked automatically, what was proposed and who approved it, and whether a change was rolled back.
- Security evidence. All of the above as a dated record per server, exportable, and mapped to control catalogs.
The UAE frameworks SecAI maps to
SecAI assesses against the official UAE Information Assurance Standard version 2.1, 134 controls across six management and nine technical families. An agent on the server can evidence parts of the technical families continuously: inventory and exposure, access, secure configuration, vulnerabilities, and monitoring and response. The management families, strategy, risk, awareness and the rest, stay human work. SecAI reports each control as verified, partly verified, needing manual verification, or not visible to a server agent. It does not turn that into a pass or a fail.
For the Personal Data Protection Law, Federal Decree-Law 45 of 2021, SecAI evidences the security-of-processing side at server level: access monitoring, integrity monitoring, vulnerability state, detection and response, each with timestamps. That timeline is also what you need if you ever have to work out what happened and when. SecAI does not locate or classify personal data.
Evidence, not certification
A tool that tells you that you are 94 percent compliant is telling you something it cannot know. Most controls in any framework are about people, policy and process, and no agent on a server can see those. SecAI states which controls it verified from the server, which it could only partly verify, and which need a person, and it says so in the report an assessor will read.
That restraint is practical rather than modest. Evidence that overstates itself gets thrown out at the first question; evidence that is exact about its own limits gets used.
Where the platform runs, and where data goes
SecAI is built in the UAE and its platform infrastructure is UAE-hosted. AI processing, the audits, fix checks and screening of flagged files, runs with OpenAI in the United States; the Trust Center and the Privacy Policy carry the exact statement.
The agent sends security metadata about the host, not your data. It does not send the contents of your databases, application files, uploads, mail or customer records, and it never sends password hashes, private keys or network packet contents. If your organisation's residency requirements do not allow AI processing outside the UAE, contact us before enabling AI audits.
What it does on the server
Exactly one action ever runs without a person: blocking an address that is attacking the server, and only on a server you have set to Automatic. An address is blocked after three sightings within thirty minutes, the block applies to that server, and it expires after 24 hours. Your own address and any address you mark as trusted are never blocked.
Everything deeper, a hardening fix, a package update, quarantining a suspicious file, waits for your approval in both modes. Approved configuration changes are made with a snapshot first and are rolled back on their own if the service does not come back healthy.
Language, support and buying
The website is published in English and Arabic. The dashboard and the evidence reports are in English.
Plans are priced in US dollars per month, with a 14-day free trial that needs no card: Starter at $69 for one server, and Business at $199 for 5 servers. UAE VAT is added at checkout and shown before you pay; the pricing page always carries the current figures.
For UAE service providers
Managed service providers, hosting companies and agencies in the UAE can run SecAI for their clients from a multi-tenant reseller console, under their own brand, with each client kept as a separate tenant.