Security & Compliance
DOO is built for enterprise deployments with flexible hosting, strong data ownership principles, and partnerships that meet the security standards of regulated industries.
01 · Where it lives
Three deployment options, each with its own residency footprint. Pick the shape that matches your governance posture.
DOO's default managed environment hosted on AWS. Secure, enterprise-grade, and optimized for performance across the region. Included in all standard packages.
Data residency
Data is hosted locally within the region by default, meeting the expectations of most clients without additional complexity.
A fully isolated environment separate from all other clients. Designed for organizations that require complete infrastructure exclusivity. Available as an add-on to standard packages.
Data residency
Clients with specific data residency requirements can request hosting in a region of their choice, accommodated during the scoping process.
Priced separately. Discuss with your account team.
DOO can deploy within a client's own infrastructure on AWS, Azure, Alibaba Cloud, or a private on-premise environment. Full control remains with the client. Available as an add-on.
Data residency
When deployed within a client's own infrastructure, data never leaves their environment. DOO has no access unless explicitly granted by the client.
Priced separately. Discuss with your account team.
02 · Data Access & PII
DOO holds no default access. Any access granted to the DOO team requires explicit client authorization.
Personally Identifiable Information (PII) refers to any data that can identify an individual, such as names, phone numbers, ID numbers, and transaction records. DOO applies PII reduction as a standard layer across its platform, ensuring that personal data is handled and processed in alignment with local data protection standards across the region.
03 · OpenAI Partnership
DOO operates under an Enterprise Data Privacy Agreement with OpenAI. Client data processed through DOO's AI models is used for processing only and is never used to train AI models. This agreement reflects the same standard held by the world's largest enterprise organizations.
04 · Common Questions
Yes. By default, data is hosted within the local region. For specific jurisdiction requirements, DOO can accommodate hosting in any region or within your own environment.
Not by default. Data lives within your environment and DOO holds no access unless you choose to grant it, for example during implementation or ongoing support.
DOO applies PII reduction as a standard layer and aligns with regional data protection principles. For specific regulatory requirements, our team can walk through the details.
No. Under DOO's Enterprise Data Privacy Agreement with OpenAI, client data is used for processing only. It is never used to train or improve AI models.
Our team can walk through specific compliance requirements, jurisdiction questions, or set up a private security review.