Skip to content

Security, Privacy and Compliance at Dataroid

Dataroid is an Al-powered digital analytics and customer engagement platform used by enterprises in financial services, airlines, and retail, shaping the experience of over 500 million users.

 

Serving high compliance industries means security is foundational to Dataroid. This Trust Center shows the measures we take to protect your data.

Compliance

Trusted by 70+ enterprise brands

Security and privacy framework

Data Protection & Isolation

Encryption in Transit & Storage Protection

Tenant Isolation

Data Retention

Native Authentication & Authorization

Role-Based Access Control (RBAC)

Multi-factor Authentication

Session Management

Password Security

Application & Product Security

Secure Software Development Lifecycle

Automated Security Scanning

Independent Penetration Testing

Secure Coding Training 

Infrastructure &
Network Security

Infrastructure Security

High Availability

Endpoint Protection

Business Continuity &
Incident Management 

Business Continuity Plan

Backup & Recovery

Disaster Recovery

Privacy &
Data Governance 

Customer-Controlled Data Collection

Regulatory Alignment

Data Residency

Corporate & 
Personnel Security

Personnel Security

Confidentiality

Customer Audit Rights

Security Monitoring &
Logging

Centralized Log Management

Audit Log Retention

Continuous Security Monitoring

AI &
Governance

AI Data Handling

Model Governance & Traceability

AI Access & Authorization

Configurable AI Architecture

FAQ

Company Information

Dataroid is an AI-powered SaaS digital analytics and customer engagement platform, enabling financial institutions and enterprises to understand user behavior and take real-time action within a single, fully managed environment designed for highly regulated industries. To meet the security, regulatory, operational, and data residency needs of these industries, Dataroid supports flexible deployment models, including managed cloud, local cloud, and on-premises options.

Dataroid is headquartered in Istanbul, Turkey, with additional offices in the Dubai, London, and Berlin.

Integration & Data Access

Dataroid integrates with customer digital channels primarily through Dataroid SDKs and secure APIs. For managed deployments, the Dataroid platform operates within its own environment and does not require administrative access to customer servers. Requirements for local-cloud and on-premises deployments are defined according to the agreed implementation and deployment architecture.
Dataroid processes digital end-user behavioral event data, such as page views, session starts, and button clicks. The platform does not automatically collect personally identifiable information, and data collection scope is explicitly defined and controlled by the customer.
Dataroid’s multi-tenant architecture enforces logical separation of data between customer organizations.
Dataroid supports flexible hosting aligned with each customer’s regulatory requirements, including deployment within Türkiye, the EU, and the GCC region. Customer data remains within the agreed jurisdiction at all times, hosted on independently certified cloud infrastructure.
Dataroid supports multiple deployment models, including managed multi-tenant local cloud, and on-premises deployments. The appropriate deployment model is selected according to each customer’s security, regulatory, data residency, operational, and integration requirements.

Access & Data Protection

Data is encrypted both at rest and in transit using industry-standard encryption. Dataroid uses multiple database and storage technologies depending on the workload. Data at rest is primarily protected through encryption at the underlying infrastructure and storage layer, such as encrypted disks, volumes, and storage services providing consistent protection regardless of the database technology in use. The specific encryption mechanism depends on the deployment and hosting environment. Data in transit is protected using TLS.
Dataroid provides native authentication and authorization capabilities, including multi-factor authentication (MFA). Authorization is managed through Dataroid’s role-based access control capabilities. Dataroid also supports LDAP integration for centralized authentication using enterprise directory services.

Security Operations

Yes. Dataroid undergoes annual external penetration testing performed by independent third-party security firms, complemented by continuous automated security scanning throughout the development lifecycle.
Dataroid holds ISO/IEC 27001:2022, SOC 2 Type II, and ISAE 3000, among other internationally recognized certifications.
No. Dataroid does not use subcontractors for the delivery of its core service.

Incident & Compliance

Dataroid notifies affected customers of confirmed security incidents in accordance with the notification timelines and procedures defined in the applicable agreement and relevant legal or regulatory requirements. Incident communications are provided through the contractually agreed communication channels.

Relevant certifications, independent assurance reports, and other security and compliance documentation can be made available to eligible customers under NDA. Customer audit rights are governed by the applicable customer agreement.

Drive your digital growth

Schedule a demo today to learn more on how we can help you unleash the potential of digital using Dataroid.