Separate by construction
Each company operates within its own PostgreSQL schema. Tenant boundaries exist at the database layer, not only as application filters.
Datum protects operational data through database-level company isolation, permission-aware workflows, immutable history, secure integrations, AI guardrails, and a security program being built toward SOC 2 readiness.
Each company operates within its own PostgreSQL schema. Tenant boundaries exist at the database layer, not only as application filters.
Role-based permissions control visibility and actions throughout the API, interface, approvals, and AI-assisted workflows.
Business mutations and integration events retain user, company, time, and context in an immutable audit trail.
Datum is building the technical controls and operating discipline required for enterprise assurance, without presenting readiness work as a completed independent attestation.
Tenant isolation, role-based access, attributable mutations, immutable audit evidence, secure configuration, and controlled integrations form the foundation of Datum's SOC 2 readiness work.
Datum's engineering and review practices are informed by OWASP Top 10 risk categories, including access control, authentication, injection, insecure design, security configuration, integrity, and security logging.
SOC 2 readiness is not a completed SOC 2 examination or attestation. The OWASP Top 10 is a security-awareness framework, not a product certification.
Datum AI inherits the user's company and permission context. Read-only analysis can respond immediately; write actions become pending actions for explicit review and confirmation.
Datum uses tenant-aware Redis caching, aggressive client-side query management, real-time invalidation, and safe cache clearing on company switches.
Edition and schema identifiers isolate shared cache entries.
Client state clears before loading another company's data.
Prefetching and invalidation balance speed with freshness.
Provider credentials are encrypted and connections are revocable.