Security & Compliance

How Dasha handles security, and — plainly — what we do and do not currently publish.

Security contact

Security questions, vulnerability reports, or a request for a DPA or BAA: security@dasha.ai. Machine-readable at /.well-known/security.txt.

Compliance status

Dasha does not currently publish formal third-party attestations such as SOC 2 Type II, ISO 27001, or a HIPAA BAA, nor documented data-retention, residency, or subprocessor terms. The use cases described elsewhere on this site — including healthcare and financial services — describe technical capability, not a compliance claim. A SOC 2 Type II audit is currently in progress with an independent auditor, with the observation window scheduled to complete in late 2026; the attestation will be published here when issued.

If you are evaluating Dasha for a regulated workload or need a Data Processing Agreement, contact security@dasha.ai for the current posture and available agreements before relying on the platform.

Data & privacy

How we handle site and account data is described in our Privacy Policy.

We use cookies for functional and analytical purposes. Please refer to our Privacy Policy for details.