Our Customer retains complete control over its data and the outputs of our AI Agent; and Dioptra will not share or disclose any data or Customer intellectual property in any form, including trained models or aggregates. Dioptra doesn’t train models on our Customer’s contracts, playbooks nor any other Customer data.
Dioptra is SOC2 Type II compliant. We strictly adhere to industry standards for data security.
Customer data is encrypted at rest & in transit.
We use AWS CloudWatch and GuardDuty for audit logs and monitoring services. Logs are collected and stored from resources, applications, and services we deploy in near-real-time. We have rules-based alerting in place. Logs are retained for up to two years.
We have Zero Data Retention Agreements with our LLM providers. They are contractually bound to not use the data for training purposes, not read nor retain any data. We have DPAs in place with all of our subprocessors that include technical and organizational measures for security.
At least once a year we engage in a thorough vulnerability assessment conducted by third party experts.