{"@":{"v":"gdom/1.2","profile":"https://dng.ai/gibberdom/gdom-1.2.json","proj":"text","index":"https://dng.ai/_gdom/manifest.json","site":"https://dng.ai/_gdom/site.gdom","self":"https://dng.ai/_gdom/platform/security/index.text.gdom"},"text":"# Security your CISO signs off on.\n\nSAML 2.0 SSO and SCIM, per-organization data isolation, and multi-cloud by design — backed by SOC 2 Type II, ISO 27001, and GDPR compliance.\n\n## Secure by design.\n\n### Enterprise identity\n\nSAML 2.0 SSO and SCIM provisioning via Okta, Entra ID, and your IdP.\n\n### Data isolation\n\nEach organization's data is logically isolated with strict access controls.\n\n### Encryption everywhere\n\nTLS 1.3 in transit and AES-256 at rest, with managed keys.\n\n### Multi-cloud by design\n\nChoose where workloads run; EU data processing is available.\n\n### API key auth\n\nScoped keys with configurable permissions, rotation, and usage monitoring.\n\n### Compliant & audited\n\nSOC 2 Type II, ISO 27001, and GDPR, with regular penetration testing.\n\n## Single sign-on, provisioned automatically.\n\nConnect your identity provider over SAML 2.0 for SSO, and let SCIM provision and de-provision users as your directory changes. End users can also sign in with email/password or OAuth via Google and Microsoft — all managed with secure tokens.\n\n## Audited, certified, and documented.\n\nThe platform is independently audited against SOC 2 Type II and certified to ISO 27001, with GDPR compliance, a DPA, and subprocessor transparency. EU data processing is available, and the platform undergoes regular penetration testing.\n\n## Isolated tenants, encrypted end to end.\n\nEach organization's data is logically isolated with strict access controls that prevent cross-organization access. Data is encrypted with TLS 1.3 in transit and AES-256 at rest. Workflow execution logs are retained for 30 days, and your data can be deleted at any time, including on account deletion.\n\n## Defense in depth, by default.\n\n### Role-based access\n\nLeast-privilege roles with full audit logging on every action.\n\n### Key rotation\n\nRotate scoped API keys and monitor usage without downtime.\n\n### Human-in-the-loop\n\nApproval checkpoints and traceability on every workflow run.\n\n### Incident response\n\nA documented response process with status reporting.\n\n## How a request stays isolated and encrypted.\n\nEvery API call is authenticated by a scoped key, routed to the calling organization's isolated data, encrypted in transit and at rest, and logged for audit — retained for 30 days.\n\n## From sign-on to audit log.\n\n### Connect identity\n\nWire up SAML 2.0 SSO and SCIM provisioning from Studio — no code required.\n\n### Run securely\n\nExecute at scale with scoped API keys, tenant isolation, and encryption.\n\n### Review & audit\n\nApprove where it matters; every action is logged, traceable, and exportable.\n\n## What teams ask before they commit.\n\nYes. Draft & Goal is independently audited against SOC 2 Type II and certified to ISO 27001, with GDPR compliance, a DPA, and subprocessor transparency. The platform also undergoes regular penetration testing, so security controls are verified by third parties rather than simply claimed.\n\nYes. Draft & Goal connects to your identity provider, including Okta and Entra ID, over SAML 2.0 for SSO, and SCIM provisions and de-provisions users automatically as your directory changes. End users can also sign in with email and password or via OAuth with Google and Microsoft, all managed with secure tokens.\n\nEach organization's data is logically isolated with strict access controls that prevent any cross-organization access. All data is encrypted with TLS 1.3 in transit and AES-256 at rest with managed keys, workflow execution logs are retained for 30 days, and your data can be deleted at any time, including on account deletion.\n\nYes. Draft & Goal is multi-cloud by design, so you choose where workloads run, and EU data processing is available for teams that need European data kept in region. GDPR compliance, a DPA, and subprocessor transparency support the data-protection review your legal and security teams will run.\n\nAPI access uses scoped keys with configurable permissions, usage monitoring, and rotation without downtime. Every call is authenticated by its key, routed to the calling organization's isolated data, encrypted in transit and at rest, and logged for audit, giving security teams a complete trail of programmatic access.\n\nShow us the workflow.We'll show you the 10x.\n\nBring the marketing workflow that eats your week. We'll build it live, with your data and your models, in 30 minutes.\n\n## Outbound links\n\n- [Book a demo →](https://dng.ai/book-demo/)\n\n- [Tour the platform](https://dng.ai/platform/)\n\n- [Draft & Goal](https://dng.ai/)\n\n- [Read the docs](https://docs.dng.ai/)\n\nSite navigation: https://dng.ai/_gdom/site.gdom\n\nFull page index: https://dng.ai/_gdom/manifest.json","links":[{"rel":"internal","href":"https://dng.ai/book-demo/","path":"/book-demo","label":"Book a demo →","gdom":"/_gdom/book-demo/index.text.gdom"},{"rel":"internal","href":"https://dng.ai/platform/","path":"/platform","label":"Tour the platform","gdom":"/_gdom/platform/index.text.gdom"},{"rel":"internal","href":"https://dng.ai/","path":"/","label":"Draft & Goal","gdom":"/_gdom/index.text.gdom"},{"rel":"external","href":"https://docs.dng.ai/","label":"Read the docs"}]}