DoAIRight
Trust Center

We do AI right — and we prove it on ourselves.

You're trusting us with the record of how your organization governs AI. Here is exactly how we protect it — and how we hold our own house to the same standard we help you meet.

Practising what we sell

DoAIRight runs its own AIMS on DoAIRight.

The management system we ask you to build is the one we operate internally: a defined scope, an AI policy, a live risk register, controls mapped to Annex A, and scheduled reviews and audits. If a control matters enough to recommend, it matters enough for us to run.

Tenant isolation by construction

Every organization's data is separated at the database level with row-level security, and each query is additionally scoped to your tenant. Isolation is enforced by the architecture, not by a single permission flag.

Encrypted in transit

All traffic between you, the application and our data stores is encrypted with TLS. Passwords are stored only as salted hashes — never in plain text.

Your content isn't training data

AI drafts are generated on request through provider APIs whose terms prohibit training on your inputs. Your AIMS content and assessment answers are never used to train third-party models.

You own and can export your data

Your policies, risks, controls and evidence belong to your organization. You can export records and request deletion at any time.

Least-privilege access

Access to systems is scoped to the minimum required to operate the service. Evidence files are served with strict content-type and download safeguards.

Secure by default

Signed, verified billing webhooks; idempotent event processing; rate limiting; and a security-reviewed codebase are part of how the platform is built.

Compliance & frameworks

We're candid about what we hold today versus what's on our roadmap — no badges we haven't earned.

ISO/IEC 42001 (AIMS)

We operate our own AI Management System on the product. Independent certification is a roadmap item; we do not currently claim certified status.

SOC 2 (Security)

The platform is built to SOC 2 Security control objectives — access control, encryption, change management, monitoring. A SOC 2 Type II examination is on our roadmap; we do not yet hold a SOC 2 report.

DPDP Act, 2023 (India)

Active compliance program: consent-based processing, data-principal rights, self-service export & erasure, and a named Grievance Officer.

GDPR-aligned

Access, correction, erasure, portability and objection rights are honored for users in scope.

DoAIRight is operated by Halyon Tech LLP. Request our current compliance status or a DPA at [email protected].

Sub-processors

We keep our supply chain small and name every provider that touches your data. The same list appears in our Data Processing Addendum.

RailwayApplication hosting & managed database
United States / EU
Google (Gemini)AI model inference (on request)
United States
GroqAI model inference (on request)
United States
RazorpaySubscription billing & payments
India
ResendTransactional & reminder email
United States
S3-compatible object storageDocument & evidence storage
Configurable region

Report a security concern · [email protected]

Governance you can show, not just claim.

See where you stand in ten minutes, then let the Digital AIMS Professional help you close the gaps.

Questions about data handling? Privacy Policy · Terms of Service