Most security pages list certifications. This post explains a design decision instead. At Donna, we try to make the secure path the only path available. When a rule can be enforced by the architecture of the system, we enforce it there, because a rule built into the system does not depend on someone remembering to follow it.
No Connection Strings
The usual way for a service to talk to a database is with a credential stored in configuration: a connection string, an API key or another secret. Secrets like these can leak, end up in a log, or stay valid long after the person who created them has moved on. Donna’s services hold no stored data-plane credentials at all. Each service proves who it is with an identity that the cloud provider issues and rotates, and the data services accept only that identity. There is no password to steal because no password exists.
Permissions Checked for the Person Asking
In many platforms, the backend connects to the database as a single system user with broad access, and access control is a filter the application is expected to apply. In Donna, each request carries who is asking, and what that person may see is checked before any data is read. In practice, this means Donna’s AI can only retrieve what the person asking is entitled to see.
No Public Route to the Data
Every data service that holds matter content, including documents, indexes, records and keys, sits on private network endpoints with public access disabled. That means there is no public route to the data at all. Someone who somehow held valid credentials would still need to be inside the network, and access inside the network is reserved for identities the platform itself issued.
Isolation Around the Work
- Access is granted per Space. Membership of a Space is the unit of access. Retrieval, realtime events and agent tools are all limited to it, beneath the model layer.
- Outward actions need approval. Actions that reach outside the firm, such as inviting an external party or delivering documents, require explicit human approval.
- Audit records are produced automatically. Agent runs, document deliveries and permission changes create their audit trail as they happen, so nobody has to remember to log them.
- Harmful files are stopped at upload. Every upload is checked before it reaches a matter. Harmful files are destroyed and cannot be uploaded again.
- Client data is kept in Australia. Forensic teams can also have a dedicated environment of their own, with data and processing in Australia and nothing leaving it.
Why We Build It This Way
Security that depends on procedure asks people to keep doing the right thing: rotate the secret, remember the filter, apply the policy. Security built into the architecture takes those tasks away. There is no secret to rotate, the permission check is part of every request for data, and the network itself enforces the policy. This matters most for smaller firms, which are the least able to staff a team to keep up the procedural work. Put simply, most of Donna’s security cannot be turned off, by us or anyone else, without rebuilding the system.
