Security
Security is not a feature.It's the architecture.
Every layer of Donna is designed to protect your work.
Data sovereignty
No model training
Your inputs, outputs, and uploaded documents are never used to train or improve any AI model. This prohibition is written into our Platform Agreement.
Full data ownership
Your data can be exported or deleted at any time. When your account closes, all data is permanently and irreversibly removed.
Security
Encrypted in transit and at rest
Your documents are encrypted in transit and at rest. Encryption is applied automatically across every storage and network layer.
Isolated agent runtime
Your Donna agent runs in an environment isolated to your account. Memory, context, and state are never shared between users.
Zero-trust architecture
Every request is authenticated, every session is scoped, and every action is logged. No implicit trust at any level.
Customer-controlled access
Access to customer data is strictly controlled and only granted to engineers with explicit written customer approval for support-related issues.
Enterprise-grade protection
Dedicated security expertise
Our in-house security team covers infrastructure, product, and operations. Continuous monitoring, 24/7 coverage, and end-to-end visibility across the platform.
Enterprise security controls
Audit logs, IP allow-listing, data lifecycle controls, and role-based access management. Standard controls required by enterprise IT and compliance teams, included by default.
Enforceable commitments
Our Security Addendum establishes binding contractual terms on data protection, access controls, and incident response.
Compliance
SOC 2 Type II
In progress
Donna implements SOC 2 Type II controls across access management, encryption, audit logging, and incident response. Formal certification is in progress.