Provider credentials are encrypted
AI provider keys and integration tokens are encrypted with AES-256-GCM before storage and are never sent to the browser, written to logs, or shown in an administrative screen.
Security
Described precisely, without borrowed certifications.
Every item below is a mechanism in the running software, not an intention.
AI provider keys and integration tokens are encrypted with AES-256-GCM before storage and are never sent to the browser, written to logs, or shown in an administrative screen.
Every read and write passes an ownership check. A request for another tenant's record is answered as not found, so record identifiers cannot be probed.
Access is decided by role at platform, organization, workspace and project level, through one shared permission check rather than scattered conditions.
An action that changes something outside DADI — sending, posting, committing, deleting — is prepared for review and executed only after explicit confirmation.
Allowances are reserved before a provider call is made, so a limit stops the request rather than reporting it afterwards.
Administrative changes, authorizations and consequential actions are written to an audit log with the account that performed them.
DADI is software you install on your own WordPress. It does not carry a SOC 2 report, an ISO certification, or a HIPAA attestation, because those describe an operating organization rather than a plugin. If your deployment needs them, they are properties of how you run the server — not of this software.
Your administrator should also review the terms of the AI providers they configure, since your prompts are sent to those providers.