
Built to pass your security review.
In short
Dynamiq holds SOC 2 and CASA Tier 2, and signs a BAA for HIPAA workloads and a DPA under GDPR. Credentials are encrypted in a Vault-based secrets manager, API keys are stored only as hashes, every agent run is traced and replayable, and the whole platform can run inside your own cloud account or data center.
Compliance
SOC 2
An independent audit of our security controls. The report is available on request under NDA.
HIPAA
Built to support HIPAA workloads. We sign a Business Associate Agreement (BAA) with covered entities.
GDPR
A Data Processing Agreement (DPA) is available, and our sub-processors are listed publicly.
CASA Tier 2
Our cloud application passed the App Defense Alliance's Cloud Application Security Assessment at Tier 2, a lab-verified review against the OWASP Application Security Verification Standard.
Identity and access
- Single sign-on
- On Enterprise, sign in through your identity provider over OpenID Connect, such as Okta or Microsoft Entra ID, limited to your verified email domains.
- Multi-factor authentication
- Each person can turn on a second factor for signing in to their account.
- Organizations, projects and roles
- Every request is checked against project membership, and management actions require an owner or admin role.
- Guests with project-only access
- Invite contractors and partners as guests who see only the projects they are added to.
- Private by default
- Chat conversations, their files and scheduled tasks are visible only to the person who owns them.
Data protection
- Encrypted secrets
- Credentials for connected systems are encrypted at rest in a secrets manager built on HashiCorp Vault, and keys never leave it.
- Hashed API keys
- Access keys and tokens are stored only as SHA-512 hashes, can expire on a date you set, and can be revoked at once.
- Retention policies
- Set an organization-wide ceiling with project overrides, and remove prompt and response content from traces immediately or after a set number of hours.
- Deletion you can rely on
- Deleting a project cuts access at once and permanently removes its data after a retention window.
Agent governance
- Traced and replayable
- Every run is recorded node by node, with inputs, outputs, cost and latency.
- Approvals
- Sensitive steps wait for a reviewer, who can edit fields before approving.
- Guardrails
- Detect PII and prompt injection before data reaches a model.
- Isolated code execution
- Agent code runs in isolated sandboxes, separated from the platform and from other customers.
Deployment
- Inside your perimeter
- Self-host on AWS, Azure, GCP, IBM Cloud, OpenShift or any Kubernetes 1.32+ cluster.
- Isolated environments
- Environments with no outside access are delivered with our engineers.
- Your models
- Choose from 29 model providers or run open models inside your own cluster.
The security review kit
Everything your security and procurement teams ask for, in one request.
Request the kit- SOC 2 report
- Data Processing Agreement (DPA)
- Business Associate Agreement (BAA)
- Architecture and self-hosting overview
- Answers to your security questionnaire
Policies
Questions and answers
Which compliance standards does Dynamiq meet?
Dynamiq holds SOC 2 and CASA Tier 2, and signs a BAA for HIPAA workloads and a DPA under GDPR. The SOC 2 report is available on request under NDA.
Can we keep all data inside our own environment?
Yes. Self-host the platform in your cloud account or data center. Outbound calls go only to the model and tool providers you configure, and isolated setups with our engineers need no outside access.
How do you handle personal data in prompts?
Guardrails detect PII and prompt injection before data reaches a model, so you can block or route those requests. Every run is traced so reviewers can see exactly what happened.
How do we report a vulnerability?
Email hello@getdynamiq.ai with the details, or contact your Dynamiq representative. We work with you on remediation and disclosure.

Bring your security team to the call.
We will walk through the architecture, the controls and the deployment model that fits your requirements.