Skip to content
Dialoga AI

Trust

Data Security

Security isn't an optional feature. It's the foundation of Dialoga AI. Every technical and architectural decision puts the protection of your employees' data first.

Every practice listed here has its proof and the date it was last checked in the Trust Center.

Encrypted connections

All traffic between your browser and the platform is protected by TLS (HTTPS). Login credentials are stored hashed, never in plain text.

Technical anonymity by design

The employee's identity is separated from their answers in reports. Individual data only appears in aggregate, above a minimum number of respondents set by the company.

AI processing with safeguards

Conversations are analyzed with Google Gemini on the paid API tier, under which Google may not use the content to improve its own products. The employee's name and email are not sent with the content being analyzed, and we do not train models on the conversations.

Isolation and monitoring

Production, staging and development environments are kept separate. Database access is restricted to internal infrastructure, and production errors are monitored continuously (Sentry).

Security practices

Mandatory automated tests before every production deploy
Access control on the principle of least privilege (multi-tenant)
Data isolated by company in every sensitive query
Auditable record of every consent accepted and every email sent
Rate limiting against endpoint abuse
Encrypted daily backup, kept for 30 days, with a monthly restore test
Separate environments: production, staging and development
Database access restricted to internal infrastructure (no exposed port)
Automatic alerts for vulnerable dependencies and automatic operating system updates
Anonymity through aggregation: the company can raise the threshold, never lower it below 3 respondents
Explicit employee consent before collection (LGPD, Article 11)
Incident response plan, with notice to Brazil's data protection authority (ANPD) and to data subjects when the LGPD requires it

Standards we follow

We don't have third-party certifications yet, such as ISO 27001 or SOC 2, nor an external penetration test. We'd rather say so here than leave the question for the meeting.

LGPDBrazil's General Data Protection Law
TLSEncrypted connections (HTTPS)
AnonymizationAggregation with a floor of 3 respondents

Subprocessors and where the data lives

The platform's servers are in the United States. International transfers follow Articles 33 to 36 of the LGPD, with contractual data protection clauses.

HostingerApplication servers and databaseUnited States
Google (Gemini)Running and analyzing conversations with AIUnited States and others
Cloudflare (R2)Audio, files and encrypted backups; DNSGlobal network
Hostinger MailTransactional email (invitations and reminders)Outside Brazil
SentryTechnical error loggingOutside Brazil

Responsible disclosure

If you found a security vulnerability in our platform, write to privacidade@dialoga.digital. We reply within 3 business days, and we are grateful for every responsible disclosure.

Questions about security? Talk to Laura
© 2026 Dialoga AI. All rights reserved.