We do AI right — and we prove it on ourselves.
You're trusting us with the record of how your organization governs AI. Here is exactly how we protect it — and how we hold our own house to the same standard we help you meet.
Practising what we sell
DoAIRight runs its own AIMS on DoAIRight.
The management system we ask you to build is the one we operate internally: a defined scope, an AI policy, a live risk register, controls mapped to Annex A, and scheduled reviews and audits. If a control matters enough to recommend, it matters enough for us to run.
Tenant isolation by construction
Every organization's data is separated at the database level with row-level security, and each query is additionally scoped to your tenant. Isolation is enforced by the architecture, not by a single permission flag.
Encrypted in transit
All traffic between you, the application and our data stores is encrypted with TLS. Passwords are stored only as salted hashes — never in plain text.
Your content isn't training data
AI drafts are generated on request through provider APIs whose terms prohibit training on your inputs. Your AIMS content and assessment answers are never used to train third-party models.
You own and can export your data
Your policies, risks, controls and evidence belong to your organization. You can export records and request deletion at any time.
Least-privilege access
Access to systems is scoped to the minimum required to operate the service. Evidence files are served with strict content-type and download safeguards.
Secure by default
Signed, verified billing webhooks; idempotent event processing; rate limiting; and a security-reviewed codebase are part of how the platform is built.
Compliance & frameworks
We're candid about what we hold today versus what's on our roadmap — no badges we haven't earned.
ISO/IEC 42001 (AIMS)
We operate our own AI Management System on the product. Independent certification is a roadmap item; we do not currently claim certified status.
SOC 2 (Security)
The platform is built to SOC 2 Security control objectives — access control, encryption, change management, monitoring. A SOC 2 Type II examination is on our roadmap; we do not yet hold a SOC 2 report.
DPDP Act, 2023 (India)
Active compliance program: consent-based processing, data-principal rights, self-service export & erasure, and a named Grievance Officer.
GDPR-aligned
Access, correction, erasure, portability and objection rights are honored for users in scope.
Sub-processors
We keep our supply chain small and name every provider that touches your data. The same list appears in our Data Processing Addendum.
Governance you can show, not just claim.
See where you stand in ten minutes, then let the Digital AIMS Professional help you close the gaps.
Questions about data handling? Privacy Policy · Terms of Service