Security

Security is not a feature.It's the architecture.

Every layer of Donna is designed to protect your work.

Data sovereignty

No model training

Your inputs, outputs, and uploaded documents are never used to train or improve any AI model. This prohibition is written into our Platform Agreement.

Full data ownership

Your data can be exported or deleted at any time. When your account closes, all data is permanently and irreversibly removed.

Security

Encrypted in transit and at rest

Your documents are encrypted in transit and at rest. Encryption is applied automatically across every storage and network layer.

Isolated agent runtime

Your Donna agent runs in an environment isolated to your account. Memory, context, and state are never shared between users.

Zero-trust architecture

Every request is authenticated, every session is scoped, and every action is logged. No implicit trust at any level.

Customer-controlled access

Access to customer data is strictly controlled and only granted to engineers with explicit written customer approval for support-related issues.

Enterprise-grade protection

Dedicated security expertise

Our in-house security team covers infrastructure, product, and operations. Continuous monitoring, 24/7 coverage, and end-to-end visibility across the platform.

Enterprise security controls

Audit logs, IP allow-listing, data lifecycle controls, and role-based access management. Standard controls required by enterprise IT and compliance teams, included by default.

Enforceable commitments

Our Security Addendum establishes binding contractual terms on data protection, access controls, and incident response.

Compliance

SOC 2 Type II

In progress

Donna implements SOC 2 Type II controls across access management, encryption, audit logging, and incident response. Formal certification is in progress.

Frequently asked questions

Serious about security?

Protect your matters with Donna.