Security & trust

Security you can verify.

Datify acts on your real business — your money, your customers, your comms. That only works if every action is bounded, reversible-or-gated, and provable. This page is how.

Read-only to start · nothing runs until you approve it · disconnect any time

Six things the software will not do to you

Not policies. Not intentions written into a prompt. These are limits and gates built into the way Datify executes, and you can see them working in the audit trail.

Execution is bounded in code, not prompts

Every action is checked against hard limits written into the software. There is a ceiling on how many records one step can change, a tighter one on things that cannot be taken back, and a daily limit per business. Go over it and the plan is blocked and handed back to a person — whatever autonomy level you are on.

Blast-radius ceiling per step
Tighter caps on irreversible actions
A daily limit per business

Nothing runs without your approval

A new workspace starts in Prepare mode: Datify writes the whole plan and then waits. You approve at the objective level before a single action runs. Autonomy is something you grant deliberately, one capability at a time, and high-impact actions keep a confirm gate even after you have granted it.

Prepare mode by default
Approval at the objective level
Confirm gates on high-impact actions

Every action is audited and reversible-or-gated

Each executed action is written to an append-only, immutable audit log — who, what, when, the parameters it used and the result it got. Reversible actions can be rolled back from that trail. Irreversible ones are held inside the caps above and always gated behind you.

Append-only, immutable log
Roll back a reversible action from the trail
Irreversible actions stay gated

Read-only by default

Connectors read context out of the tools you already use. Writes do not go back through them — they execute through Datify's own controlled data layer, which is the only place reliability can actually be guaranteed. You connect read-only to start, and you can disconnect at any time.

Connectors read, they do not write
Writes run through the Datify controlled layer
Disconnect whenever you want

Your data is yours

Export your whole workspace, or delete it entirely, at any time from Settings → Data & privacy. We never sell your data. We only use it to run the work you have asked for.

Export the workspace whenever you like
Delete it entirely, from Settings
Never sold, never used for anything else

Report a concern

Found a vulnerability, or just want a straight answer to a security question before you connect anything? Email security@datifyhq.com and we'll respond quickly.

security@datifyhq.com
A person reads it
We respond quickly
The gate

You approve the outcome. It cannot start without that.

You are not asked to sign off four hundred emails one by one. You are asked once, at the objective level, on a plan you can read in full — with the caps it is running under shown on the same screen.

New workspaces sit in Prepare mode until you say otherwise
Autonomy is granted per capability, never all at once
High-impact actions keep their confirm gate regardless
How execution works
Cipher · PREPARE MODE
Plan — held for your yes294 actions · 294 credits
Send 294 renewal remindersreversible · logged
Hold two slots per customerreversible · logged
Quote the 71 uncoveredneeds a second yes
Limits this run is bound by
Daily cap per business Records changed per step Tighter cap on sends
Over any of these, the plan stops and comes back to you instead of running.
Approve & runChange somethingNOTHING HAS RUN YET
The proof

Nothing happens off the record.

Every action an operative executes is written to an append-only, immutable log — who did it, what it did, when, the parameters it used and the result it got. Entries are added. They are never edited and never quietly removed.

Who acted, in which system, on whose approval
Reversible actions roll back from this trail
A blocked action is logged too — you see what stopped
Audit trail — append-onlyTODAY
09:02:41
Reminder sent · J. Harkness Gmail
Objective approved 08:57 · Mercier
EXECUTED
09:02:44
Record updated · certificate due Job records
Objective approved 08:57 · Mercier
EXECUTED
09:03:10
Slot held · Tue 09:00 Diary
Objective approved 08:57 · Mercier
EXECUTED
09:04:02
Quote drafted · £1,840 Job records
Waiting on you · confirm gate
HELD
09:04:19
Bulk write · 412 records Job records
Over the per-step ceiling
BLOCKED
ENTRIES ARE APPENDED · NEVER EDITED, NEVER DELETED
Read in, write through

Your tools are read. They are not written to behind your back.

Connectors pull context out of the systems you already pay for. Writes execute through Datify's own controlled data layer, because that is the only place we can guarantee an action either happened or did not. You start read-only, and you can pull a connector at any point without asking us.

See what connects
Job & quote records READ
Gmail READ
Diary READ
WhatsApp Business READ
Datify controlled layer
Every write executes here, under the caps, into the audit log.
Export or delete everything from Settings → Data & privacy
Certifications

We only claim what we can show you.

Plenty of software puts badges on this page. Everything below is a placeholder, and it stays a placeholder until there is a certificate or a report behind it that we can hand you. If a certification matters for your decision, email security@datifyhq.com and we'll tell you exactly where we are.

Read the privacy policy →
[SOC 2 TYPE II]
Not yet claimed
[ISO 27001]
Not yet claimed
[PENETRATION TEST]
Cadence not yet published
[DATA RESIDENCY]
Region not yet published
[UPTIME COMMITMENT]
No SLA published
[RETENTION POLICY]
Period not yet published
Bracketed text is a placeholder, not a claim. Nothing on this strip is in force today.

Connect one system, read one plan, and see the trail for yourself.

You can start read-only, in Prepare mode, without spending a credit. Nothing runs until you approve it, and everything that does run is written down.