Security & trust
Access controls, audit trails and lawful data handling by design
DNA WEB is built around who can see what, why an action was taken, and how it can be reviewed later. This page describes the safeguards we operate today — we do not claim certifications we have not obtained.
Access and authorization
Every action is scoped, logged and reviewable
Role-based access
Team members see only the entities and cases their role permits, configurable per organization.
Recorded lawful purpose
Workforce coverage requires a documented purpose attached to each entity before monitoring begins.
Audit log
Searches, findings, resolution actions and access changes are logged for later review, with retention tied to your plan.
Approval before action
Resolution options move forward only after a human approves them — nothing is actioned automatically on your behalf.
Data handling
What we collect, and what we do not
Public sources only
Discovery and monitoring rely on configured public sources — never private accounts, private messages or non-public records.
Evidence, not assumptions
Findings are stored with provenance and a verification state (verified, unverified or disputed), not asserted as fact.
Disclosed coverage gaps
Sources we could not lawfully or technically reach are shown in Coverage rather than silently omitted.
Retention tied to your plan
Evidence and audit-log retention follow the limits published for your plan; enterprise retention is scoped in conversation with sales.
Have a governance or procurement question?
Talk to our team about access-control configuration, audit-log retention, jurisdiction-aware workflows and integration options for your security or compliance review.