Security & data boundaries
Arbitration and dispute files carry privilege. datum's boundaries are architectural - enforced in the database and the code, written into the contract, and stated here without marketing gloss.
No data you upload to or output from datum is ever used to train any AI model of any kind. Your reviewers' decisions sharpen your instance only - nothing derived from your data reaches another customer, in any form.
No routine access to client documents exists - not for datum staff, not for any third party. Support access requires your written consent per incident, is time-boxed, and lands in an audit log you can inspect.
TLS in transit; AES-256 at rest under managed keys for the database, documents and page images. Multi-factor authentication for every user; role-based permissions inside your organisation.
Regional hosting with single-tenant and client-cloud tiers for privileged matters. One disclosed external call exists - the model API, contractually protected with no-training and zero-data-retention terms, removable on the enterprise tier.
GDPR and UAE PDPL posture documented control by control, with counsel sign-off as a launch gate. We never claim a certification we do not hold - ask for the checklist and you will get the real one, including what is still in progress.
In your deployment's region, in your organisation's tenancy - database rows and document originals under per-org isolation. Deployment tiers run from regional SaaS to your own cloud.
Never. Documents are processed at inference time only. This is contractual, and the org-scoped code paths are verifiable at diligence.
No routine access exists. Consent-gated, time-boxed support access only - and every read is written to an audit log you can inspect. Approval authority in the product is always yours: the language says 'approved by your team' because it is.
Yes. Certified deletion destroys database rows and stored originals, verifies each object is gone, and issues a written certificate with a cryptographic fingerprint. Retention follows your policy, not ours.
Row-level security fences every organisation at the database itself; the API connects as a restricted role that cannot see across tenants.
Every human override - event confirmations, citation approvals, deletions - is logged with who and when. The citation gate itself is enforced in code, not in a prompt.
A deletion run purges rows, destroys stored objects, verifies each one is gone, and writes a signed certificate - the written confirmation your engagement letter can reference.
The honest caveat, in writing: datum is pre-launch. Our compliance checklist marks every control as live today, closing at deployment, or pending counsel - and certifications (SOC 2, ISO 27001) are roadmap items funded by revenue, not claims we make early. Firms tell us the candour is the point.
Security review? Send your questionnaire, or request our security pack - policies, standard answers, and the UAE launch compliance checklist, current state marked honestly.
Request the security pack