# Built to pass your security review.

URL: https://www.getdynamiq.ai/security

> SOC 2, HIPAA, GDPR, CASA Tier 2, SSO on Enterprise, roles, encrypted secrets, isolated code execution, traced runs and self-hosting. Request the security review kit.

![The round steel door of a bank vault with its radial locking bolts](https://www.getdynamiq.ai/_next/static/immutable/media/vault-door.0vbrzzay1ghli.jpg)

Compliance, identity, data protection and agent governance, in our cloud or inside your perimeter.

[Request the security kit](https://www.getdynamiq.ai/contact?topic=security) · [Sub-processors](https://www.getdynamiq.ai/sub-processors)

In short

Dynamiq holds SOC 2 and CASA Tier 2, and signs a BAA for HIPAA workloads and a DPA under GDPR. Credentials are encrypted in a Vault-based secrets manager, API keys are stored only as hashes, every agent run is traced and replayable, and the whole platform can run inside your own cloud account or data center.

## Compliance

-   ### SOC 2
    
    An independent audit of our security controls. The report is available on request under NDA.
    
-   ### HIPAA
    
    Built to support HIPAA workloads. We sign a Business Associate Agreement (BAA) with covered entities.
    
-   ### GDPR
    
    A Data Processing Agreement (DPA) is available, and our sub-processors are listed publicly.
    
-   ### CASA Tier 2
    
    Our cloud application passed the App Defense Alliance's Cloud Application Security Assessment at Tier 2, a lab-verified review against the OWASP Application Security Verification Standard.
    

## Identity and access

Single sign-on

On Enterprise, sign in through your identity provider over OpenID Connect, such as Okta or Microsoft Entra ID, limited to your verified email domains.

Multi-factor authentication

Each person can turn on a second factor for signing in to their account.

Organizations, projects and roles

Every request is checked against project membership, and management actions require an owner or admin role.

Guests with project-only access

Invite contractors and partners as guests who see only the projects they are added to.

Private by default

Chat conversations, their files and scheduled tasks are visible only to the person who owns them.

## Data protection

Encrypted secrets

Credentials for connected systems are encrypted at rest in a secrets manager built on HashiCorp Vault, and keys never leave it.

Hashed API keys

Access keys and tokens are stored only as SHA-512 hashes, can expire on a date you set, and can be revoked at once.

Retention policies

Set an organization-wide ceiling with project overrides, and remove prompt and response content from traces immediately or after a set number of hours.

Deletion you can rely on

Deleting a project cuts access at once and permanently removes its data after a retention window.

## Agent governance

Traced and replayable

Every run is recorded node by node, with inputs, outputs, cost and latency.

Approvals

Sensitive steps wait for a reviewer, who can edit fields before approving.

Guardrails

Detect PII and prompt injection before data reaches a model.

Isolated code execution

Agent code runs in isolated sandboxes, separated from the platform and from other customers.

## Deployment

Inside your perimeter

Self-host on AWS, Azure, GCP, IBM Cloud, OpenShift or any Kubernetes 1.32+ cluster.

Isolated environments

Environments with no outside access are delivered with our engineers.

Your models

Choose from 29 model providers or run open models inside your own cluster.

## The security review kit

Everything your security and procurement teams ask for, in one request.

[Request the kit](https://www.getdynamiq.ai/contact?topic=security)

-   SOC 2 report
-   Data Processing Agreement (DPA)
-   Business Associate Agreement (BAA)
-   Architecture and self-hosting overview
-   Answers to your security questionnaire

## Policies

The documents behind our commitments.

-   [Privacy policy](https://www.getdynamiq.ai/privacy-policy)
-   [Terms of service](https://www.getdynamiq.ai/terms-of-service)
-   [Sub-processors](https://www.getdynamiq.ai/sub-processors)
-   [Cookie declaration](https://www.getdynamiq.ai/cookie-declaration-dynamiq)
-   [Platform security documentation](https://docs.getdynamiq.ai/docs/platform/administration/security)

## Questions and answers

### Which compliance standards does Dynamiq meet?

Dynamiq holds SOC 2 and CASA Tier 2, and signs a BAA for HIPAA workloads and a DPA under GDPR. The SOC 2 report is available on request under NDA.

### Can we keep all data inside our own environment?

Yes. Self-host the platform in your cloud account or data center. Outbound calls go only to the model and tool providers you configure, and isolated setups with our engineers need no outside access.

### How do you handle personal data in prompts?

Guardrails detect PII and prompt injection before data reaches a model, so you can block or route those requests. Every run is traced so reviewers can see exactly what happened.

### How do we report a vulnerability?

Email hello@getdynamiq.ai with the details, or contact your Dynamiq representative. We work with you on remediation and disclosure.

## Bring your security team to the call.

We will walk through the architecture, the controls and the deployment model that fits your requirements.

[Start free](https://app.getdynamiq.ai/signup) · [Talk to the team](https://www.getdynamiq.ai/book-a-demo)
