How we keep your data safe.
Plain statements about what Datius does with your data today. No badges, no fine print.
Sign-in and access
- Sign-in is handled by Clerk. Datius never sees or stores your password.
- Every request is checked against your membership of the organization and workspace it touches.
- Workspace roles (owner, editor, viewer) decide who can change signals, dashboards and alert rules, and who can only look.
- Organization admins manage the organization, its workspaces and billing, separately from workspace roles.
API keys
- A new key is shown once. Datius stores only its SHA-256 hash, so a key can't be read back, even by us.
- Each key belongs to one workspace and carries scopes. New keys can only send data by default.
- Keys can be given an expiry date and revoked at any time.
Your telemetry
- Telemetry is stored as Parquet files in object storage, filed under your organization and workspace.
- On Pro and Enterprise, those files can live in a storage bucket you own and control.
- Retention is enforced per plan, and on paid plans you choose how long data is kept.
Credentials you give us
- Storage bucket and SMTP credentials are encrypted at rest with AES-256-GCM.
- Encryption keys can be rotated, and stored credentials are re-encrypted under the new key.
Payments
- Payments are processed by Stripe. Card details go straight to Stripe and never reach Datius servers.
Operations
- Changes Datius staff make to accounts from the admin console are recorded in an audit log.
Found a vulnerability?
Email [SECURITY CONTACT EMAIL] with the steps to reproduce it. Please give us a chance to fix it before sharing it publicly, and don't access data that isn't yours while testing.