We take security seriously. Every byte of your Amazon data lives behind top-grade security layer, audited by Amazon itself under their hardest data protection process.
In a Tier-3+ cloud datacenter in Northern Virginia, USA (us-east-1). Every customer organization gets its own logically isolated data partition. We don't replicate your data to other regions, we don't move it offshore, and we don't share infrastructure with anyone.
Almost no one. We operate on least-privilege by default — engineers can only access systems they directly maintain, every read is audit-logged, and access to anything containing customer PII requires a documented reason and is reviewed quarterly. Support staff never see raw PII unless you explicitly grant temporary access to debug an issue.
Yes. We completed Amazon's Public PII Process — the audit required to access restricted SP-API data such as customer addresses, personal data and product customizations. Encryption, retention, key rotation, vulnerability management and incident response were all reviewed and approved by Amazon. Approval is renewed annually.
It's automatically deleted, full stop. Amazon's policy requires PII to be purged within thirty days of order shipment unless there's a legal basis to keep it longer (for example, tax records). Our pipeline enforces this automatically — the deletion job runs nightly and writes a record into your audit log every time it runs.
No. Your data is never used to train any model — ours, or anyone else's. When you use AI features inside DataDoe, we send only the minimum data needed to answer your specific question, and we route through enterprise-tier AI provider plans that contractually exclude your prompts and responses from model training.
We have a documented incident response plan and run tabletop exercises against it twice a year. If a breach affecting your data is detected, we notify you within seventy-two hours with what was accessed, what wasn't, what we've done to contain it, and what you need to do on your side. The same plan covers regulatory notifications where required.
We follow the controls required by each framework, but our formal certification stack is currently SOC 2 Type II in progress (target completion later this year). We're happy to share our security questionnaire response, penetration test summary, sub-processor list and DPA on request — most security teams accept this package while certification finishes.
Sync stops the moment you cancel. Within thirty days, all your data — including encrypted backups — is permanently removed from our systems and the deletion is verified by audit log. If you need it gone faster, request immediate deletion via the dashboard or email and we complete it within twenty-four hours, with written confirmation.
Email contact@datadoe.com or ask your account contact. The standard pack includes our DPA, sub-processor list, penetration test executive summary, vulnerability management policy, incident response summary, and our completed CAIQ questionnaire. Most teams receive it within one business day.
We'll walk you through our security setup, share compliance docs, or answer your security team's questions. Just reach out.
Every integration. Full onboarding support. If it’s not the best decision you made in 2026, you can cancel anytime.