SECURITY

Built to be trusted with the whole company.

Dutta reads your systems, so security is not a feature bolted on — it is the architecture. Here is exactly how your data is handled.

Compliance

GDPR-compliant processing, with a data-processing agreement we will sign. Our sub-processors are named in the privacy policy, each under its own agreement.

Formal third-party certification is not yet in place, and we would rather say so than imply an audit we have not completed. If your procurement process needs a security questionnaire answered in the meantime, email security@dutta.io and we will fill it in properly.

Data handling

Your workspace data is isolated per tenant, encrypted in transit (TLS 1.3) and at rest (AES-256). We never use customer data to train shared models. Retention is configurable, and deletion is complete within 30 days of request.

Card details sit outside that perimeter by design. Payments are processed by Stripe, which collects card data directly from the payer — card numbers never reach our systems, so there is nothing for us to store, and nothing for us to lose.

Access control

Every AI employee holds scoped credentials — read, write, or send, per system — and nothing beyond its mandate. SSO/SAML, SCIM provisioning, and role-based permissions are available on Company and Enterprise plans. Company Chat inherits your existing document permissions, so no one receives an answer sourced from material they cannot open.

Where people sign in with Google, Dutta receives only the identity Google returns. Connecting a Google service is a second, separate grant: you approve the OAuth scopes on Google’s consent screen, we ask for the narrowest set that will do the job, and access can be withdrawn at any time from your Google account or from inside Dutta. What we may do with what those scopes return is bound by the Google API Services User Data Policy — set out in the privacy policy.

Messaging and voice channels

Dutta is reachable on WhatsApp, Telegram, Slack, SMS, the Dutta app and by voice call — you can call Dutta, and Dutta can call you. Every one of them is attached the same way: linking is always initiated by the user and confirmed with a one-time verification code generated inside the Dutta web app, so a channel cannot be attached to an account that did not generate the code.

The chat platforms are operated by other companies — WhatsApp by Meta Platforms, Telegram by Telegram FZ-LLC, Slack by Slack Technologies — and each integration runs through that platform’s own bot interface. Linking one gives Dutta no access to the rest of your account: only the messages you send to the Dutta bot, or send in a channel you invite it into. SMS and voice calls travel over the telephone network, so a carrier moves them in transit exactly as it moves any other text or call.

What happens after they arrive is the same on every channel. Message content, voice notes and spoken turns on a call — transcribed to text so the assistant can respond — are processed solely to operate the assistant for that account. They are never used for advertising, never sold, and never shared with other users or organisations. Content is processed by Google Gemini purely to generate a response. Only a short rolling window of recent messages is retained for conversational context; older messages are discarded. Unlinking a channel from Profile → Chat Channels stops all processing on it and removes the stored context.

Every channel above is documented clause by clause in the privacy policy, which names each platform’s operator alongside the channel it runs, and separates the operators we instruct from the ones you have your own relationship with.

Anything consequential still waits for a person, whichever channel it arrived on. A voice instruction does not carry more authority than a typed one — approvals are approvals, and they are recorded the same way.

Auditability

Every action Dutta takes is logged with its inputs, sources, reasoning trail, and output. Any run can be replayed. Audit logs are exportable to your SIEM.

Responsible disclosure

Report vulnerabilities to security@dutta.io. We acknowledge within 24 hours, and we do not pursue legal action against good-faith researchers who follow coordinated disclosure.