Security and data protection
This overview describes the publicly verifiable security boundaries of DigiData, the responsibilities of customers and the safe route for questions or notifications.
Last content checked: July 27, 2026.
Technical and organizational boundaries
Tenantisolatie
DigiData uses a protected data environment per customer. Tenant context is derived server-side and not trusted as a free model argument.
Authentication and permissions
Supported resource links use OAuth where the vendor offers it. Application roles and connection permission limit who can connect or share data.
Geheimen
API keys and tokens for linked applications are stored encrypted. Passwords are not collected as a replacement for available OAuth flows.
Read-only uitvoer
OData, CSV and MCP are aimed at reading synchronized data. MCP does not provide create, update, delete or arbitrary SQL tools.
Logging
Operational logging can include time, duration, counts, error category, and correlation ID. Prompts, filter values and result rows do not belong in MCP audit data.
Current events and recovery
Sync status and last successful processing help distinguish between source lag, sync errors, and reporting issues.
Data flow
Source systems periodically synchronize to DigiData. Power BI, Excel, dashboards and authorized AI routes then read the last synchronized data.
Minimal access
Customers determine user rights, connected data sources and which ones data a report or external AI provider may receive.
Third party providers
Data that is deliberately sent to ChatGPT, Claude or another provider is also covered by the chosen contract, plan and retention policy.
What DigiData manages
- The supported source connection and synchronization.
- Tenant-based storage and technical access control.
- Availability of OData, CSV and limited MCP tools.
- Operational monitoring, fault diagnosis and revocation.
What the customer controls
- User roles, source rights and selected datasets.
- Report relationships, KPI definitions and business validation.
- Remote AI workspaces, provider contracts and data retention.
- Periodic review of active connections and access.
No unproven certification claim
DigiData makes no claims regarding ISO, SOC or otherwise on this page certification that cannot be publicly demonstrated. One read-only link reduces change risk, but takes the need for roles, data minimization and control of business don't answer away.
Security question or notification
Report a suspected problem via info@digi-data.nl. Indicate time, safe fault category, affected product route and a correlation ID when available. Do not send access tokens, API keys, prompts with company data or result rows by email.