Trust Center

Review Dapta security with confidence.

A clear public record of Dapta's stated security posture and the controlled path to request its audit report.

Request SOC 2 report
  1. Share your details
  2. Verify your work email
  3. Review and sign the NDA

Security controls, plainly stated.

This register mirrors every control currently published in Dapta's Vanta Trust Center. Items remain draft here until a Dapta reviewer verifies them.

Start with the way you use Dapta.

Choose a reading path for your evaluation. These filters change the controls we foreground; they do not change the SOC 2 scope.

Infrastructure security

21 controls listed
Unique production database authentication enforcedProduction datastores require approved secure authentication, such as a unique SSH key.Access and authentication boundariesNetwork and platform safeguards
Encryption key access restrictedPrivileged access to encryption keys is limited to authorized users with a business need.Access and authentication boundariesNetwork and platform safeguards
Unique account authentication enforcedSystems and applications require unique credentials or approved SSH keys.Access and authentication boundariesNetwork and platform safeguards

Organizational security

13 controls listed
Asset disposal procedures utilizedElectronic media with confidential information is securely purged or destroyed, with destruction documented.People and asset safeguardsPolicy enforcement
Production inventory maintainedA formal inventory of production-system assets is maintained.People and asset safeguardsPolicy enforcement
Anti-malware technology utilizedAnti-malware protection is deployed, updated, and logged on relevant systems.People and asset safeguardsPolicy enforcement

Product security

5 controls listed
Data encryption utilizedDatastores containing sensitive customer data are encrypted at rest.Encryption and assurance testingProduct security operations
Control self-assessments conductedControls are self-assessed at least annually and corrective actions are tracked against applicable timelines.Encryption and assurance testingProduct security operations
Penetration testing performedPenetration tests are performed at least annually and findings are remediated through tracked plans.Encryption and assurance testingProduct security operations

Internal security procedures

37 controls listed
Continuity and Disaster Recovery plans establishedBusiness continuity and disaster-recovery plans include communications for key-personnel unavailability.Governance processOperating cadence and evidence
Continuity and Disaster Recovery plans testedDocumented business-continuity and disaster-recovery plans are tested at least annually.Governance processOperating cadence and evidence
Cybersecurity insurance maintainedCybersecurity insurance is maintained to mitigate the financial impact of disruptions.Governance processOperating cadence and evidence

Data and privacy

3 controls listed
Data retention procedures establishedFormal procedures guide secure retention and disposal of company and customer data.Retention and deletionData classification and handling
Customer data deleted upon leavingConfidential customer data is removed from the application environment when service ends.Retention and deletionData classification and handling
Data classification policy establishedA classification policy supports appropriate protection and restricted access for confidential data.Retention and deletionData classification and handling

Service providers and subprocessors.

This register mirrors every provider currently listed in Dapta's Vanta Trust Center. AWS is identified in the SOC 2 report as a subservice provider; every legal classification remains draft until Dapta confirms it.

  • Anthropic

    Querying LLMs

    Location: US

  • OpenAI

    Querying LLMs

    Location: US

  • Amazon Web Services

    Cloud provider

    Location: US

  • Gemini

    Querying LLMs

    Location: US

  • Cursor

    Querying LLMs

    Location: US

  • Cloudflare Dashboard

    Cloud monitoring

  • GitHub

    Version control

  • Jira

    Collaboration

  • Claude

    Querying LLMs

  • Docker

    Container runtime, container image registry (Docker Hub), development environments

  • Grafana Labs

    Cloud monitoring

  • Groq

    AI inference API, LLM hosting and serving

  • GoDaddy Login

    Domain registration, DNS management, SSL certificates

  • KnowBe4

    Security awareness training, phishing simulations, compliance training

  • HubSpot

    CRM, marketing automation, sales pipeline, customer support ticketing

  • Membrane

    Engineering

  • Medical AI

    Other

  • Metabase

    Business intelligence, data visualization, SQL queries, dashboards

  • n8n.cloud

    Engineering

  • Notion

    Documentation, knowledge base, project management, internal wiki

  • Penti

    Other

  • PostHog

    Product analytics, session recording, feature flags, A/B testing

  • PandaDoc

    Document management

  • Slack

    Team messaging, channels, file sharing, integrations hub, workflow automation

  • Temporal Technologies Inc.

    Engineering

  • Stripe

    Payment processing, billing, invoicing, subscription management, financial reporting

  • Twilio

    Communications API: SMS, voice, WhatsApp, video, email (SendGrid)

  • Vanta

    Compliance automation (SOC 2, ISO 27001), security monitoring, vendor risk management

  • WorkOS

    Enterprise SSO, directory sync, admin portal, user management API

  • Deepgram

    Speech-to-text, text-to-speech, and voice intelligence APIs

  • LiveKit

    Real-time audio, video, and data infrastructure for voice applications

Need the full report?

Start a confidential request. We will verify your work email before presenting the NDA.

Request SOC 2 report