Security at Dathent
We protect your data with secure infrastructure, careful access control, and privacy-first practices.
Data Protection
Encryption in transit
All traffic between you, our APIs, and our backends is encrypted with TLS 1.2 or higher. HSTS is enforced on every public domain.
Encryption at rest
Customer data is encrypted at rest with AES-256, with keys managed by our cloud provider (Cloudflare).
Secure storage
Production data lives in isolated tenant scopes with no public network paths. Object storage buckets are private by default.
Payment security
Card payments are processed by Stripe, a PCI-DSS Level 1 certified provider. Dathent never sees or stores full card numbers.
Infrastructure
Cloud infrastructure
Dathent runs on Cloudflare's tier-1 edge network (Workers, D1, R2, Queues) across global regions. Compute is stateless and distributed; storage is replicated.
Backups
We take automated backups of customer databases with point-in-time recovery.
Monitoring
Infrastructure metrics, application logs, and audit trails feed into automated monitoring and alerting. Anomalies trigger alerts to our team.
Access Control
Account control
Each account owner controls their workspace, connected integrations, and billing. Granular multi-seat roles are on our roadmap.
Authentication
All accounts can enable time-based one-time-password (TOTP) multi-factor authentication. Passwords are never stored in plaintext — we hash them with PBKDF2-SHA256 using a unique per-user salt and verify them in constant time.
Limited internal access
Engineer access to production is restricted, authenticated, time-bound, and logged. Customer content is never accessed without an explicit support ticket.
Privacy-first practices
We do not sell user data
Your data is yours. We do not sell, rent, or trade personal information or customer content with third parties.
Minimal data access
We collect and retain only what we need to run the product. Pseudonymization and aggregation are applied wherever possible.
Secure integrations
OAuth scopes are requested at the minimum necessary level. Tokens are encrypted, rotated, and revocable from your settings.
Incident Response
Monitoring
Security signals from infrastructure, application, and identity providers stream into a central log pipeline with automated detection rules.
Response process
We follow a documented incident response process with defined severities, escalation, and customer notification where required.
Found something? Email [email protected]. We acknowledge reports within one business day and welcome coordinated disclosure.
Have a security question?
Our security team is happy to walk you through our controls, share our latest reports, or coordinate a vulnerability disclosure.
Contact Security