Security & Compliance
How Dasha handles security, and — plainly — what we do and do not currently publish.
Security contact
Security questions, vulnerability reports, or a request for a DPA or BAA: security@dasha.ai. Machine-readable at /.well-known/security.txt.
Compliance status
Dasha does not currently publish formal third-party attestations such as SOC 2 Type II, ISO 27001, or a HIPAA BAA, nor documented data-retention, residency, or subprocessor terms. The use cases described elsewhere on this site — including healthcare and financial services — describe technical capability, not a compliance claim. A SOC 2 Type II audit is currently in progress with an independent auditor, with the observation window scheduled to complete in late 2026; the attestation will be published here when issued.
If you are evaluating Dasha for a regulated workload or need a Data Processing Agreement, contact security@dasha.ai for the current posture and available agreements before relying on the platform.
Data & privacy
How we handle site and account data is described in our Privacy Policy.