Trust center
Enterprise-grade security by default
Every plan — not just Enterprise — ships with encryption in transit and at rest, PII redaction, and a strict no-training guarantee.
Certifications
Certified and audited
Data flow
What Dessa stores, and for how long
Follow a conversation through the pipeline — tap a pin at each stage, from ingest to deletion.
Ingest
Conversations and knowledge sync over TLS 1.3. PII is redacted on entry.
Store
Encrypted at rest (AES-256) in your chosen region — EU or US.
Resolve
Model calls use redacted context only; actions run through scoped tokens.
Retain
Default 24-month retention; configurable to 30 days. Deletion on request.
- 1
Ingest. Conversations and knowledge sync over TLS 1.3. PII is redacted on entry.
- 2
Store. Encrypted at rest (AES-256) in your chosen region — EU or US.
- 3
Resolve. Model calls use redacted context only; actions run through scoped tokens.
- 4
Retain. Default 24-month retention; configurable to 30 days. Deletion on request.
AI commitments
How Dessa treats your data
No training on your data
Your conversations never train models used by other customers. Ever. It’s in the contract.
EU data residency
Choose Frankfurt for storage and inference. Data never leaves the region.
PII redaction
Names, addresses and payment details are redacted before any model call.
Subprocessors
Who processes what
| Purpose | Region | |
|---|---|---|
| AWS | Hosting & storage | EU / US |
| Anthropic | LLM inference (redacted) | EU / US |
| Stripe | Billing | US |
| Postmark | Transactional email | US |
FAQ
Security FAQ
Where is my data stored?
In your chosen region — Frankfurt (EU) or Virginia (US) — encrypted at rest with AES-256.
Do model providers see raw customer data?
No. PII is redacted before any model call, and providers are contractually barred from training on your data.
Can we bring our own retention policy?
Yes — retention is configurable from 30 days to 24 months, per data category.
How do you handle vulnerabilities?
Independent pentests twice a year, a public disclosure policy, and 72-hour breach notification in the DPA.
Talk to our security team
Get the SOC 2 report, DPA and architecture review — usually within a day.