Trust center

How Dexby protects your customers’ credentials and data, where each compliance program stands, and who processes data for us.

Encrypted per credential

Each stored credential has its own encryption key, tied to its project, customer and connection.

Isolated per customer

Sessions use the accounts connected for one customer. Global accounts must be turned on for each endpoint.

Out of the prompt

Credentials never reach the model or your logs. They exist in memory for one call.

Private networks blocked

Custom MCP servers and imported APIs must resolve to public addresses, which blocks requests into private networks and cloud metadata.

Compliance

SOC 2 Type IIIn progressControls designed against Security, Availability and Confidentiality. The audit has not started.
HIPAAComing soonHealth data marking, encryption and redaction are built in. We do not sign BAAs yet.
GDPRErasure availableErasure of a customer’s credentials, connections and traces. Data processing agreement on request.
CCPAErasure availableThe same erasure path serves deletion requests.

Data and retention

Request payloadsOptional request bodies, query strings and responses. Personal-data actions require a separate opt-in. Health-data projects cannot store payloads.7 days
Request logsTool, status, timing, sizes and error code. No request bodies, query strings or responses.30 days
Turning logs offTurning logs off deletes stored request logs and payloads. Audit records and usage totals remain.Per project

Subprocessors

CompanyPurposeLocation
CloudflareHosting, network, cache, file storage and emailGlobal
Amazon Web ServicesDatabase and encryption key managementUnited States (us-east-1)
GoogleSign in with GoogleUnited States
We announce new subprocessors here 30 days before they start.