Security

Company details: Amaretto Software Labs ltd, registered in Bulgaria, VAT BG208304854, Address: Bulgaria, Varna 9000, ul. Vitosha 10, ap. 9.

At Amaretto Software Labs, security is fundamental to everything we build. We implement comprehensive security measures to protect your data, engineering knowledge, and operational integrity.

Infrastructure Security

Cloud Infrastructure

Our infrastructure is built on industry-leading cloud platforms with enterprise-grade security:

  • Microsoft Azure: Primary hosting infrastructure with SOC 2, ISO 27001, and GDPR compliance
  • Azure Blob Storage: Encrypted storage for workspace assets and operational artifacts
  • Azure Key Vault: Secure secrets and encryption key management
  • DDoS Protection: Always-on traffic monitoring and automatic network protection

Network Security

  • End-to-end TLS 1.3 encryption for all data in transit
  • Web Application Firewall (WAF) protection
  • Private network isolation for backend services
  • Regular security audits and penetration testing

Data Protection

Encryption

  • At Rest: AES-256 encryption for all stored data
  • In Transit: TLS 1.3 for all API communications
  • Database: Transparent data encryption with automated key rotation
  • Backups: Encrypted backups with geo-redundant storage

Data Isolation

We implement strict data isolation measures:

  • Logical tenant separation at the application level
  • Organization-specific encryption keys
  • Isolated workspaces and integration boundaries per organization
  • Row-level security in database operations

Application Security

Authentication & Authorization

  • Multi-factor authentication (MFA) support
  • Role-based access control (RBAC)
  • Secure session management
  • Password policies enforcing complexity requirements

Secure Development

  • Security-first development lifecycle (SDL)
  • Automated security scanning in CI/CD pipeline
  • Dependency vulnerability scanning
  • Regular security code reviews
  • Input validation and output encoding
  • Protection against OWASP Top 10 vulnerabilities

AI Security

AI Model Protection

  • Prompt injection prevention
  • Output validation and sanitization
  • Rate limiting on AI operations
  • Audit logging of all AI interactions

Data Privacy in AI

  • No training on customer data
  • Context isolation between organizations
  • Automatic PII detection and redaction
  • Ephemeral processing with no permanent storage

Operational Security

Monitoring & Incident Response

  • 24/7 security monitoring and alerting
  • Automated threat detection and response
  • Security incident response team
  • Incident response plan with defined escalation procedures
  • Regular incident response drills

Access Controls

  • Principle of least privilege
  • Regular access reviews and audits
  • Automated de-provisioning
  • Privileged access management (PAM)
  • Comprehensive audit logging

Business Continuity

Disaster Recovery

  • Automated daily backups with 30-day retention
  • Geo-redundant backup storage
  • Recovery Time Objective (RTO): 4 hours
  • Recovery Point Objective (RPO): 24 hours
  • Regular disaster recovery testing

Availability

  • 99.9% uptime SLA for Enterprise customers
  • Multi-region deployment capability
  • Automatic failover and load balancing
  • Real-time status monitoring at status.dawnhq.ai

Security Best Practices for Users

We recommend the following security practices for all Dawn users:

  • Enable multi-factor authentication on your account
  • Use strong, unique passwords
  • Regularly review access permissions in your organization
  • Keep your browser and operating system updated
  • Report suspicious activity immediately
  • Review audit logs regularly

Security Disclosure

Responsible Disclosure

We welcome security researchers to responsibly disclose vulnerabilities. If you discover a security issue:

  • Email us at contactdawnhq.ai
  • Include detailed reproduction steps
  • Allow us reasonable time to address the issue
  • We'll acknowledge receipt within 48 hours

See our dedicated Vulnerability Disclosure Policy for reporting expectations and scope details.

Contact Security Team

For security-related inquiries or to report a security issue:

Dawn Security Team
Amaretto Software Labs ltd
Email: contactdawnhq.ai

Our Security Commitment

Security is not just a feature—it's the foundation of everything we do at Amaretto Software Labs. We continuously invest in security improvements and work with the security community to ensure your data and intellectual property remain protected.

© 2025 Amaretto Software Labs ltd. All rights reserved.

Last updated: January 2025