Security overview

Security and data protection

This overview describes the publicly verifiable security boundaries of DigiData, the responsibilities of customers and the safe route for questions or notifications.

Last content checked: July 27, 2026.

Technical and organizational boundaries

Tenantisolatie

DigiData uses a protected data environment per customer. Tenant context is derived server-side and not trusted as a free model argument.

Authentication and permissions

Supported resource links use OAuth where the vendor offers it. Application roles and connection permission limit who can connect or share data.

Geheimen

API keys and tokens for linked applications are stored encrypted. Passwords are not collected as a replacement for available OAuth flows.

Read-only uitvoer

OData, CSV and MCP are aimed at reading synchronized data. MCP does not provide create, update, delete or arbitrary SQL tools.

Logging

Operational logging can include time, duration, counts, error category, and correlation ID. Prompts, filter values and result rows do not belong in MCP audit data.

Current events and recovery

Sync status and last successful processing help distinguish between source lag, sync errors, and reporting issues.

Data flow

Source systems periodically synchronize to DigiData. Power BI, Excel, dashboards and authorized AI routes then read the last synchronized data.

Minimal access

Customers determine user rights, connected data sources and which ones data a report or external AI provider may receive.

Third party providers

Data that is deliberately sent to ChatGPT, Claude or another provider is also covered by the chosen contract, plan and retention policy.

What DigiData manages

  • The supported source connection and synchronization.
  • Tenant-based storage and technical access control.
  • Availability of OData, CSV and limited MCP tools.
  • Operational monitoring, fault diagnosis and revocation.

What the customer controls

  • User roles, source rights and selected datasets.
  • Report relationships, KPI definitions and business validation.
  • Remote AI workspaces, provider contracts and data retention.
  • Periodic review of active connections and access.

No unproven certification claim

DigiData makes no claims regarding ISO, SOC or otherwise on this page certification that cannot be publicly demonstrated. One read-only link reduces change risk, but takes the need for roles, data minimization and control of business don't answer away.

Security question or notification

Report a suspected problem via info@digi-data.nl. Indicate time, safe fault category, affected product route and a correlation ID when available. Do not send access tokens, API keys, prompts with company data or result rows by email.