Trust & Security

How we handle your data.

Precise claims, honest boundaries. Everything below is backed by our tested architecture. If we have not verified it, we do not claim it.

Data location and hosting.

DeanOS is an Australian company. Here is exactly where your data lives and what "Australian" means today.

Hosting

DeanOS is hosted on Amazon Web Services (AWS). Production infrastructure runs in the ap-southeast-2 region (Sydney, Australia).

  • Application servers, database, and object storage are in ap-southeast-2
  • Backups are stored in the same AWS region
  • Infrastructure is managed via AWS CDK with auditable configuration

AI processing

AI model inference uses third-party providers (AWS Bedrock for Claude, OpenAI API, Google Gemini). Requests are sent to the provider's nearest available endpoint.

  • Not all model inference currently stays within Australia
  • We do not claim full Australian data sovereignty today
  • An Australian Control Pack is planned for the future — it will require verified AU inference, embeddings, storage, logs, backups, and subprocessors before sale

Encryption

Your data is encrypted both in transit and at rest.

  • TLS 1.2+ for all connections (HTTPS enforced)
  • AES-256 encryption at rest for database and file storage
  • OAuth tokens and credentials encrypted with per-tenant keys
  • No secrets committed to source code

Company status

DeanOS is an Australian company. Support, development, and operations are based in Australia.

  • Australian Business Number (ABN) registered
  • Support hours aligned to Australian Eastern time
  • All public pricing is in Australian dollars, excluding GST

What "Australian" does not mean yet.

We do not claim that all AI processing, model inference, embeddings, backups, logs, support access, telemetry, and third-party integrations stay within Australia. That claim requires a verified control matrix. When the Australian Control Pack is available, it will be separately priced and documented with specific guarantees. Today, "Australian company, Australian hosting" refers to infrastructure location — not universal data residency.

Tenant isolation.

Every customer's data is logically separated. One customer cannot see another customer's data.

Database isolation

Every database query is scoped to the current account. The account_id is enforced at the query layer — not just the application layer.

  • SQLAlchemy models require account_id in every query
  • No shared tables without tenant scoping
  • Automated tests verify cross-tenant access is impossible

Token and credential isolation

OAuth tokens, API keys, and credentials are encrypted per-tenant and bound to the account. One tenant's credentials are never visible to another tenant or to DeanOS staff without explicit audit justification.

File and storage isolation

Files, knowledge, and context are stored with tenant-scoped paths. S3 object prefixes include the account identifier. No shared file access between tenants.

Agent and workflow isolation

AI agents, departments, and workflows are bound to the account and project that created them. Background runs operate within the creating tenant's scope. No cross-tenant agent access.

Approval gates.

Some actions always require your explicit approval. This is by design, not an optional setting.

Actions that always require approval

  • Sending emails or messages
  • Publishing content to any platform
  • Spending money or changing ad budgets
  • Deleting data or records
  • Changing production systems or configurations
  • Moving money or modifying invoices

Actions that may run automatically

  • Reading data from connected systems
  • Analyzing, summarizing, and preparing reports
  • Drafting emails, replies, and content
  • Monitoring metrics and flagging changes
  • Scheduling and running read-only workflows

The boundary is enforced in code. Approval gates are not a configuration option — they are architectural.

Every approval is logged.

Each approval request includes: what action is requested, which workflow or agent is requesting it, what data it used, what the expected outcome is, and what happens if you reject it. Approvals and rejections are recorded in the audit history with timestamps.

Audit logging.

Every action is recorded. You can see what happened, when, by whom, and why.

What is logged

  • Every tool call and API request
  • Every approval request, approval, and rejection
  • Every agent creation, modification, and deletion
  • Every connected system authorization and revocation
  • Every background run and scheduled workflow execution
  • Login, session, and authentication events

What you can see

  • Full audit history for your account and projects
  • Which agent or workflow performed each action
  • What information was used in each action
  • Whether approval was required and the outcome
  • Export capability for audit records (Scale Ops)

Data retention and deletion.

Your data is yours. Here is how long we keep it and how you can get it back.

Retention

  • Active account data is retained as long as your subscription is active
  • Audit logs are retained for the duration of your account plus a reasonable post-cancellation period
  • Diagnostic lead data is retained separately from customer account data
  • Backups follow the same retention policy as production data

Export and deletion

  • You can export your operational history and value ledger
  • On cancellation, your data is retained for a grace period then deleted
  • Account deletion follows Australian Privacy Act obligations
  • You can request data export or deletion by contacting support

Connected systems and OAuth.

How we connect to Shopify, Meta, Klaviyo, Xero, Gmail, and Stripe.

OAuth and access

We use OAuth or official API authentication to connect to your systems. We never ask for your password.

  • Each connection requests the minimum scopes required for its workflows
  • You can revoke access at any time from within DeanOS or from the provider's settings
  • Token refresh is handled automatically and logged

Connection status labelling

Every integration is honestly labelled:

  • Live — production-ready, tested, and supported
  • Diagnostic via export — used for diagnostic analysis only via manual data export
  • Beta — functional but may have limitations; not recommended for critical workflows
  • Planned — on our roadmap; not currently available

We never show a provider logo without an honest readiness label.

Third-party providers.

The services we use to run DeanOS. This list is current as of the date on this page.

Amazon Web Services

Infrastructure, compute, database, file storage, and backups. Region: ap-southeast-2 (Sydney).

Anthropic (Claude via Bedrock)

Primary AI model for reasoning, analysis, and content generation.

OpenAI

AI model access for specific tasks. Requests may process outside Australia.

Google (Gemini)

AI model access for specific tasks. Requests may process outside Australia.

Stripe

Payment processing for subscriptions, implementation fees, and diagnostics.

Amazon SES

Transactional email delivery for notifications and internal alerts.

This list covers primary providers. Individual ecommerce connections (Shopify, Meta, Klaviyo, Xero, Gmail) use those platforms' own APIs and are subject to their terms of service and data handling.

AI outputs and limitations.

Honest expectations about what AI can and cannot do reliably.

AI outputs can be wrong

Language models generate responses based on patterns, not verified facts. They can produce plausible-sounding but incorrect information.

  • Every AI output includes source, timestamp, and assumptions where possible
  • Deterministic checks run on critical calculations
  • Financial figures are flagged as estimates until confirmed

Human review remains required

DeanOS is designed to prepare work for human approval — not to replace human judgment on consequential decisions.

  • Drafts are presented for review before sending
  • Spend recommendations require explicit approval
  • Financial actions are prepared, not executed autonomously
  • Every workflow logs its confidence level and data sources

Security incidents and contact.

If you discover a security issue or have questions about data handling.

Report a security issue

If you believe you have found a security vulnerability, please report it responsibly. Do not disclose it publicly until we have had a chance to investigate and respond.

Email: security@getdeanos.com

See also: Responsible Disclosure Policy

Data handling questions

For questions about data handling, privacy, the diagnostic process, or any claims on this page:

Email: support@getdeanos.com

See also: Privacy Policy

Ready to see your operational leaks?

Start with the A$750 diagnostic.

Five business days. Three identified leaks. 30-day automation plan. Credited toward implementation.

Apply for diagnostic