Trust center

Enterprise-grade security by default

Every plan — not just Enterprise — ships with encryption in transit and at rest, PII redaction, and a strict no-training guarantee.

Conditions · Dawn intake
Warming up
Workload
18 tasks/hr
Revenue today
0.0k
Load across the day
Warming up
12AM6AM12PM6PM
dessa@ops · beat 1/6
faq #inbox → 34 replies drafted
return #48219 → refund approved · policy:auto

Certifications

Certified and audited

Data flow

What Dessa stores, and for how long

Follow a conversation through the pipeline — tap a pin at each stage, from ingest to deletion.

  • 1

    Ingest. Conversations and knowledge sync over TLS 1.3. PII is redacted on entry.

  • 2

    Store. Encrypted at rest (AES-256) in your chosen region — EU or US.

  • 3

    Resolve. Model calls use redacted context only; actions run through scoped tokens.

  • 4

    Retain. Default 24-month retention; configurable to 30 days. Deletion on request.

AI commitments

How Dessa treats your data

No training on your data

Your conversations never train models used by other customers. Ever. It’s in the contract.

EU data residency

Choose Frankfurt for storage and inference. Data never leaves the region.

PII redaction

Names, addresses and payment details are redacted before any model call.

Subprocessors

Who processes what

PurposeRegion
AWSHosting & storageEU / US
AnthropicLLM inference (redacted)EU / US
StripeBillingUS
PostmarkTransactional emailUS

FAQ

Security FAQ

Where is my data stored?

In your chosen region — Frankfurt (EU) or Virginia (US) — encrypted at rest with AES-256.

Do model providers see raw customer data?

No. PII is redacted before any model call, and providers are contractually barred from training on your data.

Can we bring our own retention policy?

Yes — retention is configurable from 30 days to 24 months, per data category.

How do you handle vulnerabilities?

Independent pentests twice a year, a public disclosure policy, and 72-hour breach notification in the DPA.

Talk to our security team

Get the SOC 2 report, DPA and architecture review — usually within a day.