Skip to content

Security

What DADI actually does

Described precisely, without borrowed certifications.

Implemented safeguards

Every item below is a mechanism in the running software, not an intention.

Provider credentials are encrypted

AI provider keys and integration tokens are encrypted with AES-256-GCM before storage and are never sent to the browser, written to logs, or shown in an administrative screen.

Tenants are separated on the server

Every read and write passes an ownership check. A request for another tenant's record is answered as not found, so record identifiers cannot be probed.

Roles and permissions

Access is decided by role at platform, organization, workspace and project level, through one shared permission check rather than scattered conditions.

Consequential actions need consent

An action that changes something outside DADI — sending, posting, committing, deleting — is prepared for review and executed only after explicit confirmation.

Usage is metered before spend

Allowances are reserved before a provider call is made, so a limit stops the request rather than reporting it afterwards.

Actions are recorded

Administrative changes, authorizations and consequential actions are written to an audit log with the account that performed them.

What DADI does not claim

DADI is software you install on your own WordPress. It does not carry a SOC 2 report, an ISO certification, or a HIPAA attestation, because those describe an operating organization rather than a plugin. If your deployment needs them, they are properties of how you run the server — not of this software.

Your administrator should also review the terms of the AI providers they configure, since your prompts are sent to those providers.