Security

Trust is not a wrapper. It is the architecture.

domayne exists because company intelligence is too valuable to hand to someone else's cloud. The same conviction runs through every layer of how we build.

Commitments

Five commitments, in writing.

  • Your data never trains models. Off by default at the workspace level, contractual on request.
  • Drafts by default. Sends only with your approval or a specific standing permission you can change or revoke. Payments and deletion always wait for a person.
  • Every action is logged. Immutable audit trail, retained and exportable.
  • Deletion is real. Vectors and derived indexes included, with a destruction certificate.
  • SOC 2 Type II audit in progress. Full security overview available to prospective customers under NDA.

Sovereignty

Your data never leaves the deployment you choose.

The only exception is yours to make: you can switch on a frontier model for specific work, and every such call is redacted and logged.

Private deployment

On your infrastructure

domayne runs on servers you control: your data centre or your cloud tenancy. Inference happens inside your own jurisdiction on private models. No conversations, documents or company data are sent to any external AI provider.

domayne cloud

Hosted, still sovereign

We host the workspace on isolated, dedicated infrastructure with data residency where you need it. You choose the models, private, open or frontier, and the intelligence layer stays yours either way. If you opt into a frontier model, Nova redacts sensitive information before anything leaves your environment, under rules you set, and every call is logged. Change the model, keep the intelligence.

HostAfrica

Hosted infrastructure runs with HostAfrica: fully private servers with no resource sharing, in a Tier 3, ISO-accredited data centre with DDoS mitigation included. Their security and POPI statements are public.

Controls

Six controls, enforced in the platform, not in policy documents.

Isolation

Tenant isolation, enforced by the database

Row-level security makes the database boundary itself enforce isolation. One company's data is structurally invisible to another, not filtered out by application code.

Access

Deny by default

Sensitive capabilities are explicitly granted, never implicitly available. Every connector is permissioned per role: leasing sees leases, finance sees finance.

Approvals

Drafts by default

Every outbound side effect is a proposal a person approves, framed as a decision with full context, not a naked confirmation box. The one exception is a standing permission you grant for a specific kind of message, which you can see, change or revoke at any time.

Audit

Immutable audit trail

For any run: what data was retrieved, what tools were invoked, what was produced, answerable without reconstructing logs, retained and exportable.

Deletion

Hard delete, proven

Deletion includes vectors and derived indexes, not just rows. One-click export of everything you own, and a destruction certificate when you leave.

Containment

Budgets and kill switches

Every autonomous run is bounded in steps, tokens and time. A runaway is stopped, not continued. A kill switch halts the workspace immediately.

Blast radius

Every action is tiered by consequence, never by confidence.

The gate is what an action can reach, not how sure the model feels. Autonomy scales only where reversal is possible.

01

Read

Nova reads freely within its granted scope. Reversible by definition.

02

Draft

Nova writes drafts and working documents inside the workspace. Reversible, logged.

03

Reversible external

Actions with an undo, such as calendar holds and internal updates, run with automatic logging.

04

Irreversible external

Paying and deleting always wait for an explicit, well-framed human decision. Sending does too, unless you give Nova a standing permission for one specific kind of message, which you can see, change or pause at any time.

05

Privileged

High-blast-radius operations require approval plus a second judgment before anything moves.

Compliance

Compliance by construction. SOC 2 in progress.

domayne is built for organisations that answer to data protection law. In private deployments, inference and storage inside your own jurisdiction mean personal information is never routed through an external API to answer a question. Audit logging, role boundaries, hard deletion and export exist so that your own compliance obligations are practical to meet, not theoretical.

A SOC 2 Type II audit is in progress as the platform matures toward external scale. Our security overview, covering architecture, data flows, sub-processors and model policy, is available to prospective customers under NDA.

Model policy

Your data is never used to train models by default. Optional fine-tuning on anonymised internal conversations exists as a workspace-level control that is off until an administrator turns it on, and it never leaves your deployment.

Reporting a vulnerability

We take reports seriously and respond quickly. Write to security@domayne.ai.

Read the full security overview with your team.