Skip to content
Trust Center

Security posture

The security review, answered before you ask.

Attestations & certifications

Current posture, stated plainly.

Every item below is in place today. We do not list aspirational certifications, and we do not put a date on anything until the date is real.

Current

SOC 2 Type II

Annual Type II attestation covering security, availability, and confidentiality across all three deployment models. Report available under NDA.

Request the report →
Current

GDPR

DPA available, standard contractual clauses in place, EU data residency supported in Dedicated Managed SaaS and inherent in BYOC.

Request the DPA →
Current

Penetration testing

Independent third-party penetration testing on an annual cycle, with remediation tracked to closure. Executive summary shareable.

Request the summary →
Current

Encryption

TLS 1.3 in transit, AES-256 at rest. Under BYOC, encryption keys never leave your own KMS.

See architecture →
Current

Audit logging

Compliance-grade immutable logging on every connector change, credential rotation, permission grant, and visibility change.

Request log schema →
The architectural answer

Under BYOC, DigiUsher is a software provider, not a data processor.

This is the distinction that shortens a six-month vendor risk assessment to weeks. The entire platform, control plane included, runs inside your own cloud account or data center. No cost, usage, telemetry, or workload data crosses your boundary, so there is no processing agreement to negotiate over data we never hold.

Your perimeter: BYOC
Cost & usage data Billing exports, CUR, system tables, pod metrics: read in place.
DigiUsher control plane Ingestion, FOCUS store, allocation engine, dashboards: all inside your account.
Encryption keys Your KMS. Keys never leave, never shared, never escrowed.
AI telemetry Token counts and run IDs only; prompts are dropped at the ingestion boundary.
MCP endpoint Your AI assistants query locally, under your RBAC.
Audit log Immutable, in your account, queryable by your SIEM.

Nothing crosses this boundary. No cost data, no usage data, no telemetry, and no workload content reaches DigiUsher. This is why we are assessed as a software provider rather than a data processor.

Deployment

SaaS

Multi-tenant, region-selectable. Logical isolation per tenant, encrypted at rest with per-tenant keys. Suitable where no residency mandate applies.

Deployment

Dedicated Managed SaaS

Single-tenant infrastructure in a named region: dedicated VPC, dedicated database. DigiUsher operates it; you own the residency decision.

Deployment

BYOC: full feature parity

Deployed via Terraform or Helm through your own CI/CD into your account. Nothing egresses. Every capability, including the governed workflow automation and MCP endpoint, behaves identically.

Regulatory mapping

Regime Concern it raises How BYOC answers it
FCA / PRA (UK) Outsourcing and third-party risk in material arrangements; operational resilience. No data processing outside the firm's own perimeter, so DigiUsher is assessed as software supply rather than critical outsourcing.
DORA (EU) ICT third-party risk register, exit strategy, subcontracting transparency. FOCUS-native data stays in your estate and is standard-conformant, so exit is a data export you already own rather than a migration project.
MAS TRM (Singapore) Data locality and cloud outsourcing controls for financial institutions. Deployment inside the institution's own approved cloud account; no cross-border transfer introduced by the tool.
FedRAMP / IL2–IL4 (US) Authorized boundary and government data handling. BYOC runs within your existing authorized boundary rather than requiring a new external service to be authorized. DigiUsher holds no FedRAMP authorization of its own.
Works councils (DE/EU) Individual-level monitoring of employee activity. Organization-wide aggregate-only mode disables individual attribution views entirely; individual views are otherwise RBAC-gated.

This table maps the concerns these regimes raise onto the BYOC deployment model. It is not a claim of certification, authorization, or approval under any of them: BYOC makes DigiUsher a software provider rather than a data processor, which is what simplifies your vendor risk assessment.

AI data handling

We cannot leak your prompts, because we never ingest them.

Cost tools that observe AI workloads sit uncomfortably close to the most sensitive text in the enterprise. DigiUsher resolves that by architecture rather than policy: conversational content is dropped at the ingestion boundary by rule, regardless of how a connector is configured.

What DigiUsher ingests

  • Token counts: input, output, cached, batched
  • Model and deployment identifiers
  • Cost, rate, and commitment metadata
  • Agent run identifiers and durations
  • Commit attestation references for attribution
  • GPU utilization and partition telemetry

What is dropped at ingestion

  • Prompt text
  • Model responses
  • Tool-call payloads and arguments
  • Retrieved document content
  • Source code bodies (diff metadata only)
  • System prompts and instructions
Operational security

Access, subprocessors, and continuity.

Access control

Role-based access control on every surface including the MCP endpoint: an AI assistant inherits exactly the permissions of the person asking, never more. SSO via SAML and OIDC; SCIM provisioning available.

Least-privilege ingestion

Cloud connectors use read-only roles scoped to billing and metrics APIs. The governed workflow automation never holds write credentials: it raises a pull request into your repository and your approval applies it.

Subprocessors

A current subprocessor list is maintained and versioned, with advance notice of material changes. Under BYOC the list is effectively empty, as no third party touches your data. Request the list →

Business continuity

Documented recovery objectives (RTO and RPO), tested restore procedures, and multi-AZ deployment by default. The specific targets are stated in the security pack rather than published here.

Vulnerability management

Dependency and container scanning in CI, with severity-based remediation SLAs. Coordinated disclosure via security@digiusher.com.

Personnel

Background checks, annual security training, and role-scoped production access with break-glass approval and full audit trail.

Security questions, answered

The four questions every review opens with.

Is DigiUsher SOC 2 compliant?

Yes. DigiUsher maintains SOC 2 Type II attestation across all three deployment models: SaaS, Dedicated Managed SaaS, and BYOC. The report is available under NDA on request.

Does DigiUsher store our AI prompts or responses?

No. AI conversational content (prompts, responses, and tool payloads) is dropped at ingestion by architectural rule, not by configuration. DigiUsher ingests token counts, model identifiers, and cost metadata only, so prompt content cannot be retained even if a client misconfigures a connector.

Under BYOC, is DigiUsher a data processor?

No. Under Bring Your Own Cloud, the entire platform runs inside the customer's own cloud account or data center and no cost, usage, telemetry, or workload data leaves that perimeter. DigiUsher is therefore classified as a software provider rather than a data processor, which materially simplifies vendor risk assessment under FCA, PRA, MAS, DORA, FedRAMP, and IL2/IL4 regimes.

Where is DigiUsher data stored?

In SaaS, data is stored in the region you select. In Dedicated Managed SaaS, a single-tenant deployment is pinned to a named region of your choosing. In BYOC, data never leaves your own infrastructure and residency is entirely under your control.

Document requests

Request the security pack.

One request returns the whole set: SOC 2 Type II report, DPA with SCCs, penetration test executive summary, BYOC architecture brief, subprocessor list, and a completed CAIQ. Turnaround is typically one business day once an NDA is in place.

For security & risk teams

The full pack, plus a 45-minute architecture session with our engineering lead to walk your reviewers through the BYOC deployment and answer questions live.

Email security@digiusher.com

For procurement & legal

DPA, SCCs, insurance certificates, MSA template, and marketplace private-offer paperwork. If you are buying through a GSI, we will align to the MSA you already hold with them.

Email sales@digiusher.com

Prefer self-serve? Verify our current certifications and request documents directly from our live Trust Center ↗.