SECURITY

Built to be trusted with the whole company.

Dutta reads your systems, so security is not a feature bolted on — it is the architecture. Here is exactly how your data is handled.

Certifications

SOC 2 Type II (annual audit), ISO 27001, GDPR-compliant processing with a signable DPA. Reports are available under NDA — email security@dutta.io.

Data handling

Your workspace data is isolated per tenant, encrypted in transit (TLS 1.3) and at rest (AES-256). We never use customer data to train shared models. Retention is configurable, and deletion is complete within 30 days of request.

Access control

Every AI employee holds scoped credentials — read, write, or send, per system — and nothing beyond its mandate. SSO/SAML, SCIM provisioning, and role-based permissions are available on Company and Enterprise plans. Company Chat inherits your existing document permissions, so no one receives an answer sourced from material they cannot open.

Auditability

Every action Dutta takes is logged with its inputs, sources, reasoning trail, and output. Any run can be replayed. Audit logs are exportable to your SIEM.

Responsible disclosure

Report vulnerabilities to security@dutta.io. We acknowledge within 24 hours, and we do not pursue legal action against good-faith researchers who follow coordinated disclosure.