Security and data protection
This overview describes the publicly verifiable security boundaries of DigiData, customer responsibilities, and our secure channels for inquiries and disclosures.
Last content reviewed: August 17, 2026.
Technical and organizational boundaries
Tenant Isolation
DigiData logically isolates each customer's data within its multi-tenant environment. Tenant context is derived server-side from authenticated credentials and is never trusted as a free model argument.
Authentication and permissions
Supported resource connectors use OAuth2 wherever vendors support it. Application roles and connection permissions restrict who can connect or access data.
Secrets Management
API keys and tokens for linked applications are encrypted at rest and in transit. Passwords are never collected as a replacement for supported OAuth flows.
Read-Only Output
OData feeds, CSV exports, and MCP servers are strictly designed for reading synchronized data. MCP does not provide create, update, delete, or arbitrary SQL tools.
Audit Logging
Operational logs record timestamps, duration, record counts, error categories, and correlation IDs. Prompts, filter values, and result rows are excluded from MCP audit data.
Sync Status and Recovery
Detailed sync statuses and timestamps distinguish between source API delays, sync exceptions, and reporting configuration errors.
Data flow
Source systems periodically synchronize to DigiData. Power BI, Excel, dashboards, and authorized AI routes then read the last synchronized data.
Minimal access
Customers control user permissions, connected data sources, and which tables a report or external AI provider can access.
Third-party providers
Data sent to ChatGPT, Claude, or other AI providers is governed by your organization's chosen plan, contract, and provider retention policies.
What DigiData manages
- The supported source connection and synchronization.
- Tenant-based storage and technical access control.
- Availability of OData, CSV and limited MCP tools.
- Operational monitoring, fault diagnosis and revocation.
What the customer controls
- User roles, source rights and selected datasets.
- Report relationships, KPI definitions and business validation.
- Remote AI workspaces, provider contracts and data retention.
- Periodic review of active connections and access.
No unproven certification claim
DigiData makes no claims regarding ISO, SOC or otherwise on this page certification that cannot be publicly demonstrated. One read-only link reduces change risk, but takes the need for roles, data minimization and control of business don't answer away.
Security question or notification
Report a suspected problem via info@digi-data.nl. Indicate time, safe fault category, affected product route and a correlation ID when available. Do not send access tokens, API keys, prompts with company data or result rows by email.