Security and Data Handling (Public-Safe)
Last reviewed: 2026-03-18
Owner: Platform security
Source of truth:
https://dawnhq.ai/security
https://dawnhq.ai/privacy
https://dawnhq.ai/subprocessors
Applies to: security questions that are safe to answer publicly
Refresh cadence: monthly or after security copy changes
Facts
- Public security pages describe hosted infrastructure on Microsoft Azure.
- Public security pages describe Azure Key Vault for secrets and encryption key management.
- Public security pages describe AES-256 encryption at rest and TLS 1.3 in transit.
- Public security pages describe workspace isolation, RBAC, and audit logging.
- Support agent must never disclose secrets, private keys, internal endpoints, or internal implementation details beyond public docs.
FAQ snippets
- Is data isolated by workspace? Public product copy states workspace-level isolation.
- Is data encrypted? Public security pages state AES-256 at rest and TLS 1.3 in transit.
- Where should security reports go? Public security pages list
contact [at] dawnhq.ai.
- Can the assistant share internal configs? No, only public-safe guidance is allowed.
Escalation trigger
- User requests security documents, attestations, or internal architecture details not present in public docs.