Security & governance
Enterprise-grade
trust, by design.
Grounded, governed AI on your own data and infrastructure – encrypted, access-controlled, and aligned with recognised security and AI-governance standards from day one, never bolted on after go-live.
Built secure, not bolted on.
Security and compliance are part of the architecture – decided in the design phase, enforced on every layer, not a checklist added before launch.
Encryption
All data encrypted in transit (TLS 1.2+) and at rest (AES-256), across every environment.
Role-based access control
Least-privilege RBAC enforced by default on every product; SSO-ready (Google, Microsoft).
Permission-aware retrieval
Answers respect your source permissions — the assistant only surfaces what a user is already allowed to see.
Audit logs
Full audit logging of every access and data change, retained per your corporate policy.
Certifications that back the delivery.
These certifications are held by DEHA’s software-delivery organisation and govern how we build and run your deployment. Status is shown honestly — updated as each milestone completes.
ISO 27001
Information security management - audited and certified (delivery org).
Certified
CMMI Level 3
Appraised process maturity across our delivery organisation.
Appraised
PDPA-ready
Data-handling, consent and breach-notification principles built into every deployment (Singapore PDPA).
Aligned
MAS TRM
Architecture aligned to the Technology Risk Management guidelines for MAS-regulated financial-services clients.
Aligned
APPI (Japan)
Data-handling aligned to Japan's Act on the Protection of Personal Information for enterprise deployments.
Aligned
Your data stays yours.
We process personal data under Singapore’s PDPA (2012) – and GDPR where it applies to EEA users. Controller: DEHA GLOBAL PTE. LTD. For data inside your Workspace, your organisation is the controller and we act as processor.
You own your content
You keep full ownership of your documents and data. We hold a limited licence only to store, index and process them to run the service for you.
Never used to train shared models
Your content is never sold and never used to train models shared with other clients, unless you explicitly opt in.
Data residency in-region
Data stays in the cloud region you designate; no cross-border transfer without your written agreement (SCC / equivalent safeguards when it applies).
Trial data auto-deleted
Free-trial data is deleted after the trial. On deletion of content or account, related data is deleted or anonymised within a reasonable period, unless law requires longer retention.
Your rights (PDPA / GDPR)
Access, correct, delete, restrict, object, port, and withdraw consent — via info@deha-global.com; we respond within statutory timelines.
Workspace isolation
Separate, isolated environments per client — no shared multi-tenant data stores.
Governed the way Singapore expects.
Aligned – not certified – with Singapore’s Model AI Governance Framework for Generative AI. We operate along its six dimensions:
01
Accountability
Clear ownership of the deployment: named roles, DPAs, and mutual NDAs before any data is shared.
02
Data
Governed data handling — provenance, consent, residency and minimisation across the pipeline (see Data governance).
03
Trusted development & deployment
Baseline safety and hygiene in how models are integrated, tested and shipped — grounded, source-cited answers over open-ended generation.
04
Incident reporting
Monitoring plus a documented incident-response and breach-notification process, with timelines aligned to your regulatory obligations.
05
Testing & assurance
Evaluation before go-live; we support client-initiated penetration tests on your deployment environment.
06
Security
Information-security controls adapted for GenAI threat vectors – encryption, RBAC, permission-aware retrieval, audit logs.
Deploy it where your data has to live.
Run it where your policy requires – you keep the data and the keys; we run the platform to your configuration.
Answers you can defend.
Trust isn’t only infrastructure – it’s how the assistant answers.
Source-cited
Every answer cites the documents it came from, so your team can verify before they act.
No answer without a source
If the knowledge base doesn’t support it, the assistant says so instead of guessing.
Permission-aware
Retrieval respects your access rules — users only see what they’re already entitled to.
Who we rely on, and what they touch.
To run the service we use a small set of vetted sub-processors, each bound by data-protection terms and used only on our instructions. The full, named list is available on request and in our DPA.
If something goes wrong, you'll know.
Continuous monitoring, a documented response process, and breach-notification timelines aligned to your regulatory obligations – agreed per engagement.
Monitor
Access and data-change logging with anomaly monitoring across environments.
Respond
A documented incident-response runbook, customised per engagement.
Notify
Breach notification within timelines aligned to your obligations (PDPA / GDPR / sector rules).
Verify
We support client-initiated penetration tests, coordinated to avoid service disruption.
Send this to your security team.
The evidence your security and legal reviewers will ask for – available on request under NDA.
Security whitepaper
Architecture, data flows and controls in one document.
Data Processing Agreement (DPA)
Our standard DPA and sub-processor terms, including the named list.
Certificates & pen-test summary
ISO 27001, CMMI Level 3 certificates and the latest test summary.
Questions your security
& legal team will ask.
Where is our data stored?
In the cloud region you designate (AWS today; Azure on request), on-premise, or air-gapped. We don’t move data across regions without your written agreement.
Who can access our data?
Only roles you authorise, via role-based access control. Every access and change is logged and auditable.
Is our data used to train shared models?
No. Your documents and data are used only within your deployment — never to train models shared with other clients, unless you explicitly opt in.
What happens if there's an incident?
A documented incident-response process applies per engagement, including breach-notification timelines aligned to your regulatory obligations.
Can we run our own penetration tests?
Yes. We support client-initiated pen tests on your deployment environment, coordinated with our team to avoid disruption.
Do you sign NDAs and DPAs before engagement?
Yes — mutual NDAs and Data Processing Agreements are standard before any data is shared or work begins.
Which certifications do you hold?
ISO 27001, CMMI Level 3 (delivery organisation). PDPA, MAS TRM and Japan APPI are addressed by design. We’re aligned with Singapore’s Model AI Governance Framework for Generative AI.
Ready for a security deep-dive?
Start a free 3-day trial on your own data – on-premise / private cloud, auto-deleted after the trial – or send this page to your security team.