The round steel door of a bank vault with its radial locking bolts

Built to pass your security review.

Compliance, identity, data protection and agent governance, in our cloud or inside your perimeter.

In short

Dynamiq holds SOC 2 and CASA Tier 2, and signs a BAA for HIPAA workloads and a DPA under GDPR. Credentials are encrypted in a Vault-based secrets manager, API keys are stored only as hashes, every agent run is traced and replayable, and the whole platform can run inside your own cloud account or data center.

Compliance

  • SOC 2

    An independent audit of our security controls. The report is available on request under NDA.

  • HIPAA

    Built to support HIPAA workloads. We sign a Business Associate Agreement (BAA) with covered entities.

  • GDPR

    A Data Processing Agreement (DPA) is available, and our sub-processors are listed publicly.

  • CASA Tier 2

    Our cloud application passed the App Defense Alliance's Cloud Application Security Assessment at Tier 2, a lab-verified review against the OWASP Application Security Verification Standard.

Identity and access

Single sign-on
On Enterprise, sign in through your identity provider over OpenID Connect, such as Okta or Microsoft Entra ID, limited to your verified email domains.
Multi-factor authentication
Each person can turn on a second factor for signing in to their account.
Organizations, projects and roles
Every request is checked against project membership, and management actions require an owner or admin role.
Guests with project-only access
Invite contractors and partners as guests who see only the projects they are added to.
Private by default
Chat conversations, their files and scheduled tasks are visible only to the person who owns them.

Data protection

Encrypted secrets
Credentials for connected systems are encrypted at rest in a secrets manager built on HashiCorp Vault, and keys never leave it.
Hashed API keys
Access keys and tokens are stored only as SHA-512 hashes, can expire on a date you set, and can be revoked at once.
Retention policies
Set an organization-wide ceiling with project overrides, and remove prompt and response content from traces immediately or after a set number of hours.
Deletion you can rely on
Deleting a project cuts access at once and permanently removes its data after a retention window.

Agent governance

Traced and replayable
Every run is recorded node by node, with inputs, outputs, cost and latency.
Approvals
Sensitive steps wait for a reviewer, who can edit fields before approving.
Guardrails
Detect PII and prompt injection before data reaches a model.
Isolated code execution
Agent code runs in isolated sandboxes, separated from the platform and from other customers.

Deployment

Inside your perimeter
Self-host on AWS, Azure, GCP, IBM Cloud, OpenShift or any Kubernetes 1.32+ cluster.
Isolated environments
Environments with no outside access are delivered with our engineers.
Your models
Choose from 29 model providers or run open models inside your own cluster.

The security review kit

Everything your security and procurement teams ask for, in one request.

Request the kit
  • SOC 2 report
  • Data Processing Agreement (DPA)
  • Business Associate Agreement (BAA)
  • Architecture and self-hosting overview
  • Answers to your security questionnaire

Questions and answers

Which compliance standards does Dynamiq meet?

Dynamiq holds SOC 2 and CASA Tier 2, and signs a BAA for HIPAA workloads and a DPA under GDPR. The SOC 2 report is available on request under NDA.

Can we keep all data inside our own environment?

Yes. Self-host the platform in your cloud account or data center. Outbound calls go only to the model and tool providers you configure, and isolated setups with our engineers need no outside access.

How do you handle personal data in prompts?

Guardrails detect PII and prompt injection before data reaches a model, so you can block or route those requests. Every run is traced so reviewers can see exactly what happened.

How do we report a vulnerability?

Email hello@getdynamiq.ai with the details, or contact your Dynamiq representative. We work with you on remediation and disclosure.

Bring your security team to the call.

We will walk through the architecture, the controls and the deployment model that fits your requirements.