Buyer FAQ
Answers for security, procurement and records teams
Straight answers about data boundaries, certifications, Arabic documents, air-gapped operation, pricing shape and how an engagement starts.
What is iDocHive?
iDocHive is a governed document and knowledge intelligence platform. It helps organizations digitize, classify, search and ask questions over sensitive archives inside an approved environment — on-premise, private or sovereign cloud, or air-gapped — with citations, permissions and audit evidence.
Who is it for?
Ministries, authorities, national and institutional archives, infrastructure programs, and other regulated enterprises that cannot send production documents to public AI services.
Does our data leave our environment?
By design, production document processing stays inside the customer-approved boundary. Deployments are sold for customer-controlled topologies: on-premise, private or sovereign cloud, or air-gapped. Models, keys, prompts, responses and audit records remain under customer control per the contracted design. Any optional connectivity, for example updates or approved integrations, is defined in the deployment architecture — not assumed.
Do you require a public AI API?
No. Sovereign and air-gapped deployments run on customer-approved local models. Where a customer's policy allows broader routing, the AI Gateway can enforce which models are approved — including keeping sensitive content inside the boundary and redacting before any allowed egress. The security boundary is a product decision, not an afterthought.
Are you ISO certified?
Creation Next, the company behind iDocHive, holds ISO 9001 and is ISO 27001 certified. Certification covers the organization's information security management system; it does not by itself make a customer deployment compliant. Jurisdiction-specific mapping, for example Saudi PDPL and NCA control frameworks, is done per tender and topology. Certificate details and scope are available on request.
Does iDocHive make us PDPL or NCA compliant?
No software makes an organization compliant by itself. iDocHive is designed to support customer compliance programs and control mapping — including Saudi PDPL and NCA ECC, DCC and CCC where cloud infrastructure applies. Controller and processor roles, retention and evidence remain customer responsibilities, supported by product controls and deployment design.
How do you handle Arabic documents?
The platform is built for Arabic and English, including mixed documents: OCR, indexing, search and bilingual workflows. Low-confidence OCR can be routed to human review before content becomes searchable intelligence. Exact quality depends on document condition and the approved OCR and model stack for your deployment — validated in a Proof of Value on your samples.
What happens when the system is unsure?
The correct outcome may be refusal, escalation, uncertainty or a human-review task. The system is designed not to invent missing evidence. Low OCR confidence goes to a validation queue; a restricted collection returns access denied; conflicting sources are presented with citations; missing evidence returns an insufficient-evidence response; a high-impact output stays pending approval.
Can we run fully air-gapped?
Yes. Air-gapped designs use internal inference, approved model packages and signed offline updates for application, OCR and models, with checksums, provenance and rollback. No production internet egress is part of that topology.
How do updates work without internet?
Isolated environments receive signed offline packages. Transfer follows customer media-transfer approval. Packages are verified before apply, and rollback is part of the update lifecycle.
Who owns encryption keys?
Encryption in transit and at rest is baseline. Customer-controlled keys are supported where required by policy. Key custody is agreed in the architecture review and RACI.
How does access control work?
Identity integrates with the customer identity provider where available, including single sign-on and MFA via the IdP. Role-based access, least privilege and collection- or record-level restrictions apply. Retrieval is permission-aware: unauthorized collections do not enter answer context.
Do you keep an audit trail?
Yes. Ingestion, access, inference, approval, export and administrative events can be recorded and streamed to the customer SIEM by syslog, API or an approved agent, per deployment.
Will you train models on our documents?
Customer content is not used for training without explicit authorization. An approved-model registry tracks versions, prompt policy and evaluation expectations for the deployment.
How does procurement usually start?
We recommend starting with one document collection and one measurable outcome, then: discovery, sovereign document assessment, a paid Proof of Value, security and architecture validation, production, training, staged handover and support. Software, services, infrastructure and digitization should remain separable line items.
What is a Proof of Value?
A time-boxed, paid exercise on agreed sample documents — non-production or approved samples — inside a defined security boundary. Success measures are written up front, for example retrieval quality, OCR review rate, time-to-answer and citation usefulness. Confidential production archives are not uploaded through the public website.
What do you need from us for a Proof of Value?
A clear use case and success measures; the security boundary and topology preference (private, sovereign or air-gap); a document profile covering languages, formats, volume estimate and quality; identity and, if relevant, SIEM expectations; and named owners for security, records, business and IT. Please do not send confidential files through the public contact forms.
How is pricing structured?
Pricing is tailored to scale, security boundary and hosting model. Typical commercial shapes include a department Pilot, an organization-wide Enterprise deployment on private infrastructure, and Sovereign air-gapped or classified environments. Request an architecture review or a quote — list prices are not published because topology drives cost.
What is Creation Next's role versus ours or a local partner's?
Creation Next provides product software, solution architecture, deployment support, pipelines and workflows, agreed integrations, training, support and update packages. The customer provides infrastructure unless contracted otherwise, identity and network, data ownership, lawful processing, subject-matter experts, role approval, security policy and acceptance. A local systems integrator, where agreed, handles local contracting, infrastructure delivery, Arabic business analysis, on-site support and change management. Every proposal converts this into a named RACI.
How do I start?
Book an architecture review on this site, email business@idochive.com, or call +966 50 769 4941. Tell us the use case, boundary, document profile and success measures — not confidential document contents.
Certificate details and scope are available on request.