Security

How we approach protecting your data and our systems.

Infrastructure

DONNA runs on modern cloud infrastructure with encrypted transport (HTTPS), managed access controls, and isolated environments for production workloads. Vendor services are configured following least-privilege principles.

Authentication & access

Member access uses industry-standard authentication. Administrative access is limited, logged, and reviewed as appropriate for the product stage. Secrets and keys are stored in secure environment configuration, not in source code.

AI safety & oversight

DONNA uses confirmation-aware workflows, permission boundaries, recipient resolution, and controls designed to reduce prompt-injection risk from retrieved emails, documents, and websites. Action and activity records support oversight; available audit views depend on the deployment and configuration.

The real-estate setup guide explains how to start with conservative permission boundaries and expand only after testing.

Reporting issues

If you believe you have found a security vulnerability, please email derek@aidonna.co with a concise description and steps to reproduce. We appreciate responsible disclosure.

Last updated: April 19, 2026