Control connections
Configure which tools, servers, and IPs Dash can connect with.
Security
Dash runs in a dedicated sandbox that acts like a fence. Automatically deployed and transparent to you.
Configure which tools, servers, and IPs Dash can connect with.
Set every operation to Auto, Ask, or Off on each connection.
Make a connection workspace-wide or limit it to its connector and invited teammates.
SOC 2 Type IIAttested
ISO/IEC 27001Certified Connection governance
Every integration passes through two independent checks. Both are enforced server-side each time Dash acts, not just displayed in the dashboard.
Who may use this connection?
Everyone in the Dash workspace may use the connection.
Only the connector and teammates they invite may use it.
What may each operation do by default?
Fetch, list, and search. Runs without a prompt by default.
Create, update, send, or post. Pauses for human approval by default.
Permanent deletion, purge, force-push, or repository and branch removal.
Routine edits stay reviewable. Operations such as deleting spreadsheet rows or removing a label remain in the Write tier and default to Ask rather than Off.
Security Gate FAQ
No. New Gmail and Outlook connections start private to the connector and teammates they invite, regardless of the workspace's general sharing setting. Existing email connections keep their current scope until someone changes it.
Irreversible destructive operations default to Off. An authorized workspace member must deliberately enable one before Dash can use it. Routine reversible edits remain in the Write tier and default to Ask.
Yes. Access scope and run mode are independent settings on each connection. Authorized members can share a private connection or move a specific operation between Auto, Ask, and Off.
Dash enforces both checks server-side at execution time across Pipedream, GitHub, and custom MCP connections. The controls are not only visual settings in the dashboard.
How Dash is built
Dash runs work in an isolated sandbox that limits where information can move. The sandbox is the fence between AI capability and your systems.
Every Dash workspace runs in its own execution context. Data never crosses workspace boundaries. Two customers running Dash share zero state.
Dash uses OAuth where supported and keeps tool access revocable. You can disconnect a tool in one click.
Reads run automatically by default. Routine writes pause for approval, while irreversible destructive operations start Off until someone deliberately enables them.
Sensitive workspace credentials are encrypted at rest, handled server-side, and only used when Dash needs to act on your behalf.
Conversations and tool outputs stay yours. We use model APIs with training opt-out enabled across the board.
Wipe your entire Dash workspace, including memory and history, with one command. Deletion is irreversible and complete within 24 hours.
Independent assurance
Dash is SOC 2 Type II attested and ISO/IEC 27001 certified, with independently verified controls for security and information risk management.
Reports and supporting materials are available to customers and prospects on request.
SOC 2
ISO/IEC 27001
Security documentation
Yes. Dash is SOC 2 Type II attested, covering the design and operating effectiveness of applicable controls over a review period.
Yes. Dash is ISO/IEC 27001 certified and operates a certified information security management system.
Yes. Customers and qualified prospects can request the SOC 2 report, ISO/IEC 27001 certificate, security overview, and supporting materials from our team.
Sub-processors
We use a short list of trusted vendors. All sub-processors are reviewed annually.
Ask for our security overview deck or send a question to the team.