Security & Privacy

Security and privacy, by design.

Dossier plugs into the tools your team already uses, so we hold your data and credentials to the standard that access demands. Here's exactly how we protect them, in plain language.

CASA Tier 2 assessed AES-256 encryption Hosted in the US No training on your data
01

You're in control

You decide which tools Dossier connects to, and you can revoke any connection at any time. When you do, Dossier's access ends immediately.

You choose the connectionsRevoke anytime
02

Credentials the model never sees

Your credentials live in an encrypted vault (HashiCorp Vault, backed by AWS KMS). They're attached server-side only at the moment a tool runs, so the AI model never sees them. Revoke a connection and the stored credentials are deleted.

HashiCorp VaultAWS KMSAttached server-sideDeleted on revoke
03

Encrypted in transit and at rest

Your data is encrypted with AES-256 at rest and TLS in transit, running entirely on AWS infrastructure in the United States.

AES-256 at restTLS in transitAWS · United States
04

Scoped to your organization

Your data, credentials, connections, and agents are scoped to your organization and never shared across customers. Every agent run executes in an isolated, ephemeral container that's destroyed when the work is done.

Per-organization scopeEphemeral containers
05

Never used to train AI

Dossier does not train AI models on your data. We use Anthropic and OpenAI models for agent reasoning, tool use, and composing Slack replies, all under API terms that prohibit training on your data.

AnthropicOpenAINo training on your data
06

Access follows the person

For personal connectors like Gmail, each teammate connects their own account, so Dossier only ever sees what that person can see. Team-wide connectors, like enrichment providers, can be shared, and you control how they're set up.

Per-user accountsShared team connectorsYou control config
07

Only the channels you invite it to

Dossier sees only the channels it's invited to. The messages you send it, and their thread context, are stored as conversation history. Slack access tokens live in the same encrypted vault and are deleted when you uninstall Dossier from your workspace.

Invited channels onlyTokens deleted on uninstall
Independently assessed

Dossier has passed Google's CASA Tier 2 security assessment.

The Cloud Application Security Assessment (CASA) Tier 2 framework evaluates third-party cloud apps against rigorous OWASP Application Security Verification Standards (ASVS).

Subprocessors

We work with a small, vetted set of subprocessors to run Dossier.

SubprocessorPurpose
AWSHosting and infrastructure
AnthropicAI models
OpenAIAI models
ClerkAuthentication
StripeBilling

Questions we hear from customers

Dossier uses models from Anthropic and OpenAI for agent reasoning, tool use, and composing replies in Slack. All usage falls under API terms that prohibit training on your data.

Have a security or compliance question?

We're happy to walk your team through any of this in more detail.

Email hello@usedossier.online