datum

Security & data boundaries

Ensure complete confidentiality.

Arbitration and dispute files carry privilege. datum's boundaries are architectural - enforced in the database and the code, written into the contract, and stated here without marketing gloss.

No AI model training.

No data you upload to or output from datum is ever used to train any AI model of any kind. Your reviewers' decisions sharpen your instance only - nothing derived from your data reaches another customer, in any form.

No staff access. No third-party monitoring.

No routine access to client documents exists - not for datum staff, not for any third party. Support access requires your written consent per incident, is time-boxed, and lands in an audit log you can inspect.

Encryption everywhere.

TLS in transit; AES-256 at rest under managed keys for the database, documents and page images. Multi-factor authentication for every user; role-based permissions inside your organisation.

Your jurisdiction. Your tenancy.

Regional hosting with single-tenant and client-cloud tiers for privileged matters. One disclosed external call exists - the model API, contractually protected with no-training and zero-data-retention terms, removable on the enterprise tier.

Compliance without theatre.

GDPR and UAE PDPL posture documented control by control, with counsel sign-off as a launch gate. We never claim a certification we do not hold - ask for the checklist and you will get the real one, including what is still in progress.

The four questions every firm asks

Straight answers, in writing.

Where is our data stored?

In your deployment's region, in your organisation's tenancy - database rows and document originals under per-org isolation. Deployment tiers run from regional SaaS to your own cloud.

Are our documents used for AI training?

Never. Documents are processed at inference time only. This is contractual, and the org-scoped code paths are verifiable at diligence.

Can datum staff read our files?

No routine access exists. Consent-gated, time-boxed support access only - and every read is written to an audit log you can inspect. Approval authority in the product is always yours: the language says 'approved by your team' because it is.

Can our data be permanently deleted?

Yes. Certified deletion destroys database rows and stored originals, verifies each object is gone, and issues a written certificate with a cryptographic fingerprint. Retention follows your policy, not ours.

Under the hood

Controls you can verify, not just read about.

Isolation by construction

Row-level security fences every organisation at the database itself; the API connects as a restricted role that cannot see across tenants.

Auditability

Every human override - event confirmations, citation approvals, deletions - is logged with who and when. The citation gate itself is enforced in code, not in a prompt.

Certified deletion

A deletion run purges rows, destroys stored objects, verifies each one is gone, and writes a signed certificate - the written confirmation your engagement letter can reference.

The honest caveat, in writing: datum is pre-launch. Our compliance checklist marks every control as live today, closing at deployment, or pending counsel - and certifications (SOC 2, ISO 27001) are roadmap items funded by revenue, not claims we make early. Firms tell us the candour is the point.

Security review? Send your questionnaire, or request our security pack - policies, standard answers, and the UAE launch compliance checklist, current state marked honestly.

Request the security pack