Decionis is built for enterprise teams that need transparent controls, auditable decisions, and a clear security roadmap.
Control mapping and evidence collection are in progress for SOC 2 readiness.
Data minimization and deletion workflows are implemented; formal DPA and residency options are in progress.
ISO 27001 controls are on the roadmap as part of enterprise readiness work.
Enterprise security built into every layer — not bolted on after the fact.
Traffic is encrypted in transit. At-rest encryption depends on your cloud/database configuration.
Decision inputs, outputs, and workflow events are stored for audit and review.
Org-scoped RBAC is live with OWNER, ADMIN, MEMBER, and VIEWER roles enforced across tenant APIs.
OIDC and SAML tenant identity are available, including signed state, metadata import, and ACS hardening checks.
Org-scoped API keys, scoped permissions, tenant authorization checks, and optional deployment-level rate limiting are available.
Regional data residency options are planned for enterprise deployments.
Decionis doesn't just make decisions — it documents them. Every output is auditable, defensible, and reversible.
Full provenance for every decision. See exactly what inputs drove each output.
Decision history is available via API. Custom export formats are supported during pilots.
Retention and deletion requests are handled through documented operational workflows.
We only collect what's needed for decision-making. No tracking pixels, no third-party analytics on your decision data.
Your decision inputs are never used to train AI models. Your data stays yours.
Request complete deletion of your data at any time. We'll remove everything within 30 days.
Full list of subprocessors available. We notify you before adding new ones.
Talk to our team about your security requirements, custom integrations, and compliance needs.