Trust
Data Security
Security isn't an optional feature. It's the foundation of Dialoga AI. Every technical and architectural decision puts the protection of your employees' data first.
Every practice listed here has its proof and the date it was last checked in the Trust Center.
Encrypted connections
All traffic between your browser and the platform is protected by TLS (HTTPS). Login credentials are stored hashed, never in plain text.
Technical anonymity by design
The employee's identity is separated from their answers in reports. Individual data only appears in aggregate, above a minimum number of respondents set by the company.
AI processing with safeguards
Conversations are analyzed with Google Gemini on the paid API tier, under which Google may not use the content to improve its own products. The employee's name and email are not sent with the content being analyzed, and we do not train models on the conversations.
Isolation and monitoring
Production, staging and development environments are kept separate. Database access is restricted to internal infrastructure, and production errors are monitored continuously (Sentry).
Security practices
Standards we follow
We don't have third-party certifications yet, such as ISO 27001 or SOC 2, nor an external penetration test. We'd rather say so here than leave the question for the meeting.
Subprocessors and where the data lives
The platform's servers are in the United States. International transfers follow Articles 33 to 36 of the LGPD, with contractual data protection clauses.
Responsible disclosure
If you found a security vulnerability in our platform, write to privacidade@dialoga.digital. We reply within 3 business days, and we are grateful for every responsible disclosure.