Technical

Security by Architecture

by Prasad Hemakumara2 September 20267 min read

Most security pages list certifications. This post explains a design decision instead. At Donna, we try to make the secure path the only path available. When a rule can be enforced by the architecture of the system, we enforce it there, because a rule built into the system does not depend on someone remembering to follow it.

No Connection Strings

The usual way for a service to talk to a database is with a credential stored in configuration: a connection string, an API key or another secret. Secrets like these can leak, end up in a log, or stay valid long after the person who created them has moved on. Donna’s services hold no stored data-plane credentials at all. Each service proves who it is with an identity that the cloud provider issues and rotates, and the data services accept only that identity. There is no password to steal because no password exists.

Permissions Checked for the Person Asking

In many platforms, the backend connects to the database as a single system user with broad access, and access control is a filter the application is expected to apply. In Donna, each request carries who is asking, and what that person may see is checked before any data is read. In practice, this means Donna’s AI can only retrieve what the person asking is entitled to see.

Youyour identityyour accessAppAPIAgentsyour accessyour accessprivate network boundaryYour datadocuments, index, matterno public endpoint exists
Access checked on every request
Each request carries who is asking, and their access is checked on the way to the data. The data layer has no public way in.

No Public Route to the Data

Every data service that holds matter content, including documents, indexes, records and keys, sits on private network endpoints with public access disabled. That means there is no public route to the data at all. Someone who somehow held valid credentials would still need to be inside the network, and access inside the network is reserved for identities the platform itself issued.

Isolation Around the Work

  • Access is granted per Space. Membership of a Space is the unit of access. Retrieval, realtime events and agent tools are all limited to it, beneath the model layer.
  • Outward actions need approval. Actions that reach outside the firm, such as inviting an external party or delivering documents, require explicit human approval.
  • Audit records are produced automatically. Agent runs, document deliveries and permission changes create their audit trail as they happen, so nobody has to remember to log them.
  • Harmful files are stopped at upload. Every upload is checked before it reaches a matter. Harmful files are destroyed and cannot be uploaded again.
  • Client data is kept in Australia. Forensic teams can also have a dedicated environment of their own, with data and processing in Australia and nothing leaving it.

Why We Build It This Way

Security that depends on procedure asks people to keep doing the right thing: rotate the secret, remember the filter, apply the policy. Security built into the architecture takes those tasks away. There is no secret to rotate, the permission check is part of every request for data, and the network itself enforces the policy. This matters most for smaller firms, which are the least able to staff a team to keep up the procedural work. Put simply, most of Donna’s security cannot be turned off, by us or anyone else, without rebuilding the system.

See Donna on the work your firm does

Country *
Organisation type *
Firm size *
How did you hear about us?

For details about how we collect, use, and protect your information, see our privacy policy.