How we keep your data safe.

Plain statements about what Datius does with your data today. No badges, no fine print.

Sign-in and access

  • Sign-in is handled by Clerk. Datius never sees or stores your password.
  • Every request is checked against your membership of the organization and workspace it touches.
  • Workspace roles (owner, editor, viewer) decide who can change signals, dashboards and alert rules, and who can only look.
  • Organization admins manage the organization, its workspaces and billing, separately from workspace roles.

API keys

  • A new key is shown once. Datius stores only its SHA-256 hash, so a key can't be read back, even by us.
  • Each key belongs to one workspace and carries scopes. New keys can only send data by default.
  • Keys can be given an expiry date and revoked at any time.

Your telemetry

  • Telemetry is stored as Parquet files in object storage, filed under your organization and workspace.
  • On Pro and Enterprise, those files can live in a storage bucket you own and control.
  • Retention is enforced per plan, and on paid plans you choose how long data is kept.

Credentials you give us

  • Storage bucket and SMTP credentials are encrypted at rest with AES-256-GCM.
  • Encryption keys can be rotated, and stored credentials are re-encrypted under the new key.

Payments

  • Payments are processed by Stripe. Card details go straight to Stripe and never reach Datius servers.

Operations

  • Changes Datius staff make to accounts from the admin console are recorded in an audit log.

Found a vulnerability?

Email [SECURITY CONTACT EMAIL] with the steps to reproduce it. Please give us a chance to fix it before sharing it publicly, and don't access data that isn't yours while testing.