Dash

Security

Puppies need a fence.

Dash runs in a dedicated sandbox that acts like a fence. Automatically deployed and transparent to you.

Dash, the AI puppy, safely behind a fence

Control connections

Configure which tools, servers, and IPs Dash can connect with.

Granular permissions

Set every operation to Auto, Ask, or Off on each connection.

People-aware access

Make a connection workspace-wide or limit it to its connector and invited teammates.

SOC 2 Type IIAttested
ISO/IEC 27001Certified

Connection governance

The Security Gate controls who can use a connection and what it can do.

Every integration passes through two independent checks. Both are enforced server-side each time Dash acts, not just displayed in the dashboard.

Enforced server-side Pipedream GitHub Custom MCP
Access scope

Who

Who may use this connection?

Workspace access

Everyone in the Dash workspace may use the connection.

Private access

Only the connector and teammates they invite may use it.

Run mode

What

What may each operation do by default?

Read

Fetch, list, and search. Runs without a prompt by default.

AutoRuns automatically
WriteWrite

Create, update, send, or post. Pauses for human approval by default.

AskPauses for approval
DestructiveDelete

Permanent deletion, purge, force-push, or repository and branch removal.

OffEnable deliberately

Routine edits stay reviewable. Operations such as deleting spreadsheet rows or removing a label remain in the Write tier and default to Ask rather than Off.

Security Gate FAQ

Connection controls, answered.

Are Gmail and Outlook connections shared with the workspace by default?

No. New Gmail and Outlook connections start private to the connector and teammates they invite, regardless of the workspace's general sharing setting. Existing email connections keep their current scope until someone changes it.

Can Dash delete data by default?

Irreversible destructive operations default to Off. An authorized workspace member must deliberately enable one before Dash can use it. Routine reversible edits remain in the Write tier and default to Ask.

Can the Security Gate defaults be changed?

Yes. Access scope and run mode are independent settings on each connection. Authorized members can share a private connection or move a specific operation between Auto, Ask, and Off.

Where is the Security Gate enforced?

Dash enforces both checks server-side at execution time across Pipedream, GitHub, and custom MCP connections. The controls are not only visual settings in the dashboard.

How Dash is built

Security your team can verify.

Dedicated sandbox execution

Dash runs work in an isolated sandbox that limits where information can move. The sandbox is the fence between AI capability and your systems.

Workspace isolation

Every Dash workspace runs in its own execution context. Data never crosses workspace boundaries. Two customers running Dash share zero state.

OAuth where supported

Dash uses OAuth where supported and keeps tool access revocable. You can disconnect a tool in one click.

Run modes for every operation

Reads run automatically by default. Routine writes pause for approval, while irreversible destructive operations start Off until someone deliberately enables them.

Encrypted credential storage

Sensitive workspace credentials are encrypted at rest, handled server-side, and only used when Dash needs to act on your behalf.

No training on your data

Conversations and tool outputs stay yours. We use model APIs with training opt-out enabled across the board.

Clean workspace on demand

Wipe your entire Dash workspace, including memory and history, with one command. Deletion is irreversible and complete within 24 hours.

Independent assurance

Independent assurance for the systems behind Dash.

Dash is SOC 2 Type II attested and ISO/IEC 27001 certified, with independently verified controls for security and information risk management.

Reports and supporting materials are available to customers and prospects on request.

SOC 2

Type II attested

Control design and operating effectiveness independently examined.

ISO/IEC 27001

Certified ISMS

A certified system for managing information security risk.

Security documentation

What your team can review.

SOC 2 Type II

Attested

ISO/IEC 27001

Certified

Security overview

Available on request

Privacy requests

Supported

Data processing terms

Available on request

Regional hosting options

Enterprise

Vendor review support

Available on request

Compliance questions, answered.

Is Dash SOC 2 Type II attested?

Yes. Dash is SOC 2 Type II attested, covering the design and operating effectiveness of applicable controls over a review period.

Is Dash ISO 27001 certified?

Yes. Dash is ISO/IEC 27001 certified and operates a certified information security management system.

Can my security team review the reports?

Yes. Customers and qualified prospects can request the SOC 2 report, ISO/IEC 27001 certificate, security overview, and supporting materials from our team.

Sub-processors

Who Dash works with.

We use a short list of trusted vendors. All sub-processors are reviewed annually.

  • Anthropic AI model provider
  • OpenAI AI model provider
  • Microsoft Azure Cloud provider
  • AWS Cloud provider
  • Pipedream OAuth & integration catalog
  • Cloudflare DNS, CDN & WAF
  • Resend Transactional email
  • Stripe Payment processing

Security questions?

Ask for our security overview deck or send a question to the team.