Security and trust

Trust is not a setting.
It is the architecture.

Datum protects operational data through database-level company isolation, permission-aware workflows, immutable history, secure integrations, AI guardrails, and a security program being built toward SOC 2 readiness.

01

Separate by construction

Each company operates within its own PostgreSQL schema. Tenant boundaries exist at the database layer, not only as application filters.

02

Least privilege by default

Role-based permissions control visibility and actions throughout the API, interface, approvals, and AI-assisted workflows.

03

Traceable without exception

Business mutations and integration events retain user, company, time, and context in an immutable audit trail.

Built for assurance.
Clear about the stage.

Datum is building the technical controls and operating discipline required for enterprise assurance, without presenting readiness work as a completed independent attestation.

SOC 2
Readiness program in progress

Controls designed toward SOC 2

Tenant isolation, role-based access, attributable mutations, immutable audit evidence, secure configuration, and controlled integrations form the foundation of Datum's SOC 2 readiness work.

OWASP TOP 10
Risk-informed engineering

Application security shaped by real web risks

Datum's engineering and review practices are informed by OWASP Top 10 risk categories, including access control, authentication, injection, insecure design, security configuration, integrity, and security logging.

SOC 2 readiness is not a completed SOC 2 examination or attestation. The OWASP Top 10 is a security-awareness framework, not a product certification.

Protection at every layer.

IDENTITYAuthenticated sessions and unified company identityControlled selection across companies and editions
AUTHORIZATIONRole and object-aware access controlPermissions enforced at the API and workflow level
APPLICATIONCSRF protection and validated business transitionsControlled mutations and approval boundaries
DATASchema-per-company isolation and encryptionTenant-aware cache keys prevent cross-company reads
EVIDENCEImmutable operational and integration audit historyAttributable actions for compliance and investigation

The assistant does not get a security exception.

Datum AI inherits the user's company and permission context. Read-only analysis can respond immediately; write actions become pending actions for explicit review and confirmation.

AI action control

Draft purchase requisition for 200 units of SKU-1234

  • User can view product and vendor
  • User can create requisitions
  • Company context: Northstar Fabrication
  • ! Confirmation required before creation

Fast without compromising boundaries.

Datum uses tenant-aware Redis caching, aggressive client-side query management, real-time invalidation, and safe cache clearing on company switches.

Tenant-aware cache keys

Edition and schema identifiers isolate shared cache entries.

Safe company switching

Client state clears before loading another company's data.

Current operational state

Prefetching and invalidation balance speed with freshness.

Secure accounting tokens

Provider credentials are encrypted and connections are revocable.

Bring your architecture and compliance questions.

Talk with the Datum team