Security you can hand to your compliance team

We take security seriously. Every byte of your Amazon data lives behind top-grade security layer, audited by Amazon itself under their hardest data protection process.

Amazon PII approved

Restricted PII access granted & audited

Pre-approved by Amazon to pull customer addresses, customizations and gift messages on behalf of every connected seller.

AES-256-GCM at rest

Authenticated-encryption-grade cipher

Every database row, every cached file, every backup encrypted with AES-256-GCM — the authenticated cipher used by the U.S. government for classified data.

TLS 1.3 in transit

Modern transport security

Continuously monitored cipher suites. Weak protocols refused. Every API call, every dashboard session, every Amazon connection.

DPP audited

Amazon Data Protection Policy verified

Encryption, retention, key rotation, vulnerability management and incident response — all audited by Amazon under the Public PII Process.

Penetration testing program

Third-party security firm engagement

External pen tests on data-flow components, scheduled on annual cycle. Reports archived; findings remediated and re-verified.

Continuous vulnerability monitoring

Automated scans across all data flows

Continuous monitoring for unusual access patterns and emerging vulnerabilities, with scheduled deep scans across all components.

Where your data lives

U.S. infrastructure. One organization per vault.

Your DataDoe data lives on AWS and GCP infrastructure in the United States (Tier-3+ datacenters, primary region Northern Virginia, us-east-1) — physically isolated, redundantly powered, continuously monitored. Every customer organization gets its own logically separated data partition.

This isn't a permission setting we could accidentally turn off. It's how the database is architected: cross-organization access is impossible by design, not just disallowed. You see your data. Nothing else, ever.

Primary: AWS us-east-1 (N. Virginia) Warehouse: GCP BigQuery (US) Tier: Tier-3+ datacenters Architecture: per-org isolation Backups: encrypted, redundant
AOrganization A · your teamyour data
BOrganization B · separate vaultisolated
COrganization C · separate vaultisolated
DOrganization D · separate vaultisolated
no path between them
+Every new customer · their own vaultautomatic
Cross-organization access is impossible by design.
Encryption

At rest. In transit. In your hands.

Three independent encryption layers protect your data across its entire lifecycle in DataDoe — applied automatically, enforced everywhere, monitored continuously.

/ 01

At rest

AES-256-GCM

Every database row, every cached file, every backup — encrypted with AES-256-GCM, the authenticated cipher used by the U.S. government for top-secret data classification.

Always on
/ 02

In transit

TLS 1.3

Every API call, every dashboard session, every Amazon connection. We continuously monitor cipher suites and refuse weak protocols. No exceptions, no downgrade attacks.

Enforced everywhere
/ 03

Credentials

AWS Secrets Manager

Your Amazon connection credentials, API keys, and database secrets live in AWS Secrets Manager — separated from data, rotated on cycle, never hardcoded in source. Continuous monitoring flags any unusual access.

Auto-managed
✓ GDPR Article 28 aligned ✓ UK GDPR + IDTA incorporated ✓ CCPA Service Provider terms ✓ Amazon SP-API DPP approved
Amazon Public PII
Amazon Public PII ✓ Approved

We passed Amazon's hardest data audit so you don't have to.

To pull customer addresses, customizations and personal data from Amazon SP-API, every organization must complete the Public PII Process — a months-long, multi-stage audit covering encryption, retention, access controls, vulnerability management and incident response. Here's exactly what was reviewed.

Restricted Data Token (RDT) infrastructureEvery PII request short-lived, scoped per resource
AES-256-GCM encryption at restEvery byte of customer data, including all backups
TLS 1.3 encryption in transitContinuous monitoring · weak ciphers refused
Encryption key rotationAWS Secrets Manager · separated from data store
30-day PII retention enforcementLifecycle automation · audit trail required
Penetration testing programThird-party security firm · annual cycle · reports on file
Continuous vulnerability monitoringAutomated scans · scheduled deep scans across components
Least privilege access policyEngineers see only systems they directly maintain
Quarterly access reviewsAll employee accounts · access revoked within 24 hours of termination
Incident response planDocumented procedure · regular tabletop exercises
48-hour breach notification SLATighter than 72-hour GDPR default
Audit logging for every PII accessEvery read · every export · every API call logged
Binding contractual terms in DPA · Subprocessor list in Annex C · Full Trust Center at /legal
AI data isolation

AI sees the answer. Not your warehouse.

How DataDoe handles your data when you use AI features inside the platform — and when you connect your own AI tool through MCP, REST API, or SDK.

Platform AI

Only what's needed to answer.

When you use AI features inside the DataDoe app — daily briefs, ask-anything chat, suggested actions — we send only the minimum data the model needs to answer your specific question. Never your full warehouse.

  • Per-question scoped data extraction
  • No PII unless explicitly queried
  • No raw exports passed to the model
  • Every call written to your audit log
Claude · Cursor · Codex · ChatGPT · MCP

You decide what gets sent.

When you connect Claude, Cursor, Codex, ChatGPT or any AI tool through MCP or our REST API, the tool requests what it needs and we send only that. You set the scope. You see every call. You revoke access in one click.

  • Granular field-level access control
  • Per-integration scopes you define
  • Every request logged in your dashboard
  • Revoke any key any time, instantly
Your data is never used to train AI models.

Not by us. Not by the AI providers we connect to, when configured properly through their enterprise plans — which we recommend and document for every supported provider.

Account security

Strong defaults. No exceptions.

Every user account, every API key, every integration.

/ 01

Two-factor authentication

Every user can set up 2FA with any TOTP authenticator app — Google Authenticator, Authy, 1Password, hardware keys. MFA is enforced for all DataDoe staff with infrastructure access.

TOTP via authenticator app · supported on all plans · MFA enforced for admin/cloud access · enabled in 30 seconds
/ 02

Keys you see once

Every API and MCP key is generated, shown to you a single time, then permanently hidden — even from us. Lose it, you regenerate.

Max 1-year TTL · auto-expire · regenerate any time · never readable after creation
/ 03

Least privilege by default

Every team member gets a scoped role. Every integration gets the narrowest permissions needed. Quarterly access reviews across all employee accounts.

Org-level + table-level + integration-level scopes · quarterly reviews · 24-hour revocation on termination · full audit trail
Data lifecycle

Your data leaves the way you want it to.

Clear retention rules. No surprises. No "we keep it for analytics purposes" small print.

NOW
Active subscription
Your data lives in DataDoe

Encrypted at rest, accessible via dashboard, API, MCP, SDK and BigQuery.

T+0
You cancel
Subscription ends

Sync from Amazon stops. No new data added. Your existing data marked for deletion.

T+30d
Final cleanup
Permanent removal

All your data — including backups — permanently removed from our systems, verified by audit log.

Buyer PII: 30 days after order delivery

Customer names and addresses from Amazon orders are auto-deleted no later than 30 days after delivery — separate from your subscription lifecycle, in line with Amazon's SP-API Data Protection Policy.

Or delete on demand, any time

Request immediate full deletion via dashboard or email. Completed and confirmed within 24 hours, audit-logged. Plus: export your full historical dataset in CSV or JSON before you go — no lock-in, ever.

🛡
48-hour breach notification SLA

If a confirmed security incident affects your data, we notify you within 48 hours of confirmed awareness — tighter than the 72-hour GDPR default — with the information you need to meet your own notification obligations.

FAQ

Where exactly is my data stored?

Faq Plus

Who at DataDoe can actually see my data?

Faq Plus

Is DataDoe an Amazon-approved developer for restricted data?

Faq Plus

What happens to PII data after thirty days?

Faq Plus

Does DataDoe use my data to train AI models?

Faq Plus

What happens if there's a data breach?

Faq Plus

What about SOC 2, ISO 27001, GDPR, HIPAA?

Faq Plus

How fast does deletion actually happen if I cancel?

Faq Plus

Where can I get the security documentation pack?

Faq Plus

Need more details?

We'll walk you through our security setup, share compliance docs, or answer your security team's questions. Just reach out.

Set up in under
5 minutes.
Try free for 7 days. Then $97/month.

Every integration. Full onboarding support. If it’s not the best decision you made in 2026, you can cancel anytime.