Dossier plugs into the tools your team already uses, so we hold your data and credentials to the standard that access demands. Here's exactly how we protect them, in plain language.
You decide which tools Dossier connects to, and you can revoke any connection at any time. When you do, Dossier's access ends immediately.
Your credentials live in an encrypted vault (HashiCorp Vault, backed by AWS KMS). They're attached server-side only at the moment a tool runs, so the AI model never sees them. Revoke a connection and the stored credentials are deleted.
Your data is encrypted with AES-256 at rest and TLS in transit, running entirely on AWS infrastructure in the United States.
Your data, credentials, connections, and agents are scoped to your organization and never shared across customers. Every agent run executes in an isolated, ephemeral container that's destroyed when the work is done.
Dossier does not train AI models on your data. We use Anthropic and OpenAI models for agent reasoning, tool use, and composing Slack replies, all under API terms that prohibit training on your data.
For personal connectors like Gmail, each teammate connects their own account, so Dossier only ever sees what that person can see. Team-wide connectors, like enrichment providers, can be shared, and you control how they're set up.
Dossier sees only the channels it's invited to. The messages you send it, and their thread context, are stored as conversation history. Slack access tokens live in the same encrypted vault and are deleted when you uninstall Dossier from your workspace.
The Cloud Application Security Assessment (CASA) Tier 2 framework evaluates third-party cloud apps against rigorous OWASP Application Security Verification Standards (ASVS).
We work with a small, vetted set of subprocessors to run Dossier.
| Subprocessor | Purpose |
|---|---|
| AWS | Hosting and infrastructure |
| Anthropic | AI models |
| OpenAI | AI models |
| Clerk | Authentication |
| Stripe | Billing |
Dossier uses models from Anthropic and OpenAI for agent reasoning, tool use, and composing replies in Slack. All usage falls under API terms that prohibit training on your data.
We're happy to walk your team through any of this in more detail.
Email hello@usedossier.online