TRUST · SECURITY · GOVERNANCE
Security is not a feature.
DK1.AI systems touch revenue, legal, and financial workflows. This page documents how we build, deploy, and govern them. It is the first thing any serious operator asks.
Data handling
DEPLOYMENTScoped per engagement. Customer-owned or DK1-managed tenant isolation is documented in the release packet.
TRAININGNo model training on your data. Customer data is handled for inference and service delivery. DK1 contracts permit no model-training use.
ENCRYPTIONIn transit today. Encryption at rest for self-hosted systems and backups is planned. Key management is scoped per engagement.
RETENTIONSet per engagement. Retention for model inputs is agreed during scoping and documented in the release packet.
Access control
SSOPlanned. WorkOS-based SSO is not yet enabled in production. Identity-provider setup is scoped during onboarding.
RBACScoped by default.No user sees data their role shouldn't see — enforced before the model reads it.
AUDITExportable audit trail. Governed workflows record approvals and material actions.
SESSIONSession expiry. Sessions expire after a set period and end on logout.
AI governance
APPROVALHuman in the loop on any customer-facing output. Configurable per workflow.
PROVENANCESources, always. Every generated artifact links back to the documents that grounded it.
GUARDRAILSContent + topic filters. Tuned per deployment — what the system may and may not discuss.
OVERRIDEPer-workspace kill switch. Held by your named reviewer. Global incident controls are documented per deployment.
Operations
SUPPORTSet in your agreement. Support targets are defined in the customer agreement and launch runbook.
MONITORINGEnd-to-end traces. Classification accuracy, draft quality, SLA drift — all dashboarded.
INCIDENTRunbook-defined. Escalation and root-cause reporting follow the runbook for your deployment.
DISCLOSUREEmail security@dk1.ai. Security findings go straight to the team that builds the system.
COMPARED
What a DK1 build gives you that a SaaS AI doesn't.
CAPABILITYDK1 BUILDSAAS AIIN-HOUSE
Tenant isolation documented per engagement
No training on your data
Exportable audit trail
Workflow-specific tuning
Ships in weeks, not quarters
Operated by the builder
COMPLIANCE · OUTCOME COMMITMENTS
What we are honest about.
SOC 2
DK1.AI is not currently SOC 2 certified.
What is in place today, and what is still planned:
- ›Access management
- ›Exportable audit trail of approvals and material actions
- ›Encryption in transit
- ›Planned: least-privilege separation of admin and service accounts
- ›Planned: encryption at rest for self-hosted systems and backups
We have begun SOC 2 readiness work; no audit has started.
OUTCOMES
We do not guarantee revenue outcomes.
DK1.AI does not guarantee revenue lift, deal velocity, close rate, or specific business outcomes. We commit to what we ship:
- ›Working agents, deployed to the architecture scoped for your engagement
- ›An exportable audit trail of approvals and material actions
- ›Human approval gates on every customer-facing output
- ›Measurable operational metrics — first-response SLA, meeting-booked rate, pipeline coverage, review-cycle health
Outcomes depend on your team, your market, and your offer. Any vendor promising guaranteed revenue lift on an AI deployment is selling you something other than software.
Have a security questionnaire?
Send it to us. A DPA and subprocessor list will be available on request once finalized.
Send questionnaire →