Controls aligned to global frameworks.
Dainin AI is committed to strong operational, security, and privacy practices. Our controls are designed to align with globally recognised compliance frameworks, giving you confidence in how your data is handled.
Overview
GDPR
Designed to operate in accordance with GDPR principles
SOC 2
Security controls aligned with SOC 2 Trust Services Criteria
ISO/IEC 27001
Security practices aligned with ISO 27001 framework
Infrastructure Security
Built on enterprise cloud providers maintaining SOC and ISO certifications
Trust Services Criteria
Our security controls are designed to align with the five SOC 2 Trust Services Criteria, providing a foundation for operational trust and accountability.
Information and systems are protected against unauthorised access, disclosure, and damage through security controls.
Infrastructure and systems are available for operation and use as committed or agreed.
System processing is complete, valid, accurate, timely, and authorised to meet objectives.
Information designated as confidential is protected throughout its lifecycle.
Personal information is collected, used, retained, disclosed, and disposed of in conformity with commitments.
Information Security Management
Our security practices are aligned with the ISO 27001 framework, covering key domains of information security management.
Documented information security policies reviewed and updated on a regular cycle.
Role-based access controls, least-privilege enforcement, and regular access reviews.
Continuous risk assessment, treatment plans, and risk register maintenance.
Change management, capacity planning, malware protection, and logging controls.
Defined incident response procedures with escalation paths and post-incident reviews.
Data Protection
Dainin AI is designed to operate in accordance with GDPR principles, ensuring personal data is handled lawfully, transparently, and securely.
Personal data is processed with a valid legal basis and for specified, legitimate purposes.
Only data that is necessary for the stated purpose is collected and processed.
Appropriate technical and organisational measures protect personal data against unauthorised processing.
Personal data is retained only for as long as necessary to fulfil its processing purpose.
Mechanisms exist to support access, rectification, erasure, restriction, and portability requests.
Infrastructure
Dainin AI is built on enterprise-grade cloud infrastructure from providers that maintain industry-leading compliance certifications.
Primary cloud infrastructure with SOC 1/2/3, ISO 27001, and additional certifications.
Compute and infrastructure services with SOC 1/2/3, ISO 27001, and additional certifications.
Vendor Management
All third-party vendors and subprocessors are evaluated for security, privacy, and compliance before onboarding, and reviewed on an ongoing basis.
Continuous Improvement
Compliance is not a one-time exercise. We continuously assess and improve our controls to meet evolving regulatory requirements and security standards.
Periodic internal reviews and readiness assessments against target frameworks.
Security and privacy policies reviewed and updated on a regular cycle.
Continuous risk assessment with documented treatment plans and tracking.
Monitoring of regulatory changes to ensure ongoing alignment with requirements.
Questions?
For compliance-related questions, audit requests, or to request our security documentation, please contact our security team.
security@dainin.ai