Security & compliance

How Dasha handles security, and — plainly — what we do and do not currently publish.

Security contact

Security questions, vulnerability reports, or a request for a DPA or BAA: security@dasha.ai. Machine-readable at /.well-known/security.txt.

Compliance status

ItemStatus
SOC 2 Type IINot published
ISO 27001Not published
HIPAA BAAAvailable for eligible healthcare deploymentsContact security@dasha.ai
Data retention, residency and subprocessor termsNot published

Dasha does not currently publish formal third-party attestations such as SOC 2 Type II or ISO 27001, nor documented data-retention, residency, or subprocessor terms. The use cases described elsewhere on this site — including healthcare and financial services — describe technical capability, not a compliance claim.

We sign HIPAA Business Associate Agreements (BAAs) for eligible healthcare deployments. If you need one, are evaluating Dasha for a regulated workload, or need a Data Processing Agreement, contact security@dasha.ai for the current posture and available agreements before relying on the platform.

Data & privacy

How we handle site and account data is described in our Privacy Policy.

We use cookies for functional and analytical purposes. Please refer to our Privacy Policy for details.