No over-promises on this page. Only what works.
You’re probably here because someone on the growth team sent you a link. Fair. This page explains how AppDNA handles your data and your users — as mechanisms, not assurances. Where something is a scoped engagement rather than a standard feature, we say so. Where a certification is in progress rather than earned, we say that too.
AppDNA’s security model rests on mechanisms, not promises: multi-tenant isolation enforced in code at the query level, an AI that cannot change anything users see without human approval, experiments constrained by staged rollouts and automatic stop-losses, and a data flywheel designed so anonymized market patterns flow in while nothing identifiable about your app ever flows out.
Mechanisms, not assurances.
Every workspace is isolated at the query and tool-execution level: each read and write is scoped to your tenant before it executes. Isolation isn’t a rule employees follow or a filter applied after the fact — it’s how the system is built, so cross-tenant access isn’t a violation, it’s a query that cannot run. Audit data and optimization data are kept separate too.
No other customer — and no AI action running on another customer’s behalf — can touch your data, because the code path for doing so does not exist.
The flywheel is asymmetric by design: anonymized market learning flows in to your recommendations; your raw data never flows out. Your inputs are never used to train a shared model. Cross-app benchmarks use only anonymized, statistically aggregated patterns, with minimum cohort sizes enforced before any pattern is shared.
You benefit from patterns across the market (“apps like yours convert trials at X”), but nothing identifiable about your app, funnel, or numbers is ever visible to — or learnable by — anyone else.
The system reads and analyzes freely — that’s its job. Anything that changes what your users see is approval-gated: a named human on your team approves it, and it’s logged. Destructive actions are deny-listed outright. Auto-mode is an explicit opt-in constrained to guardrails you define, with hard cost caps.
If your users saw it, someone on your team approved it — or explicitly opted into the bounded guardrails that allowed it. Either way, the audit trail shows who, what, and when.
Every experiment ships through the same safety pipeline: rollouts start at 10% of traffic; a KPI stop-loss watches your guarded metrics and automatically halts and withdraws anything that hurts them; rollback is instant, served from configuration; and SRM detection flags broken experiments before anyone reads a false result.
The worst realistic case is 10% of traffic for the short window before the stop-loss fires — then it’s withdrawn automatically and the record is in the log. Safer than build → submit → hope.
For organizations whose compliance requirements go beyond shared SaaS: dedicated single-tenant instances in your chosen data-residency region, customer-managed encryption keys (CMEK), SSO/OIDC, private networking — up to deployment inside your own cloud. These are scoped engagements, delivered with your security team against agreed milestones; never sold as turnkey, never dated before scoping.
Dedicated, compliance-grade deployment is a conversation that starts with your requirements document — not a checkbox on a pricing page.
GDPR-aligned data handling; a Data Processing Agreement (DPA) available for review; a maintained subprocessor list; data deletion on termination covered in the DPA. SOC 2: not yet certified — we’re on the enterprise-readiness track, and until it’s earned you won’t see the badge here. What we offer meanwhile is what most reviews actually check: isolation enforced in code, audit trails, the DPA, and direct answers to your questionnaire.
Ask us where the certification process stands and we’ll tell you plainly — we’d rather pass your review with the truth than fail your audit with a claim.
What the SDK does — and doesn’t — collect.
The AppDNA SDK uses public APIs only and is App Review-safe. It renders approved changes natively and reports the funnel events needed to measure them. It is deactivated by configuration: if you switch it off, your app keeps running in its last approved state — no emergency release.
Four questions security teams ask us first.
01Is our data used to train AI models?
Not shared ones, ever. Your data improves recommendations for your workspace. The only thing that crosses tenant boundaries is anonymized, statistically aggregated pattern data with enforced minimum cohort sizes — designed so no customer can be identified from it. Nothing identifiable flows out.
02Can the system change our app without anyone approving it?
No — not unless you explicitly opt into auto-mode, and even then only inside guardrails you define, with hard cost caps, deny-listed destructive actions, and a full audit trail. By default, every user-facing change requires a named human’s approval.
03What happens if an experiment goes wrong in production?
It starts at 10% of traffic, a KPI stop-loss halts and withdraws it automatically if a guarded metric suffers, and rollback is instant because changes are served from configuration, not shipped in a release. SRM detection catches broken experiments before they produce misleading results.
04Do you have SOC 2 / can you pass our vendor review?
SOC 2 is not yet certified — we’re on the enterprise-readiness track and will say exactly where it stands if you ask. Vendor reviews we support today with the DPA, the subprocessor list, architecture answers on isolation and encryption, and — where requirements demand it — dedicated isolated deployments scoped with your team. Send the questionnaire; we answer it ourselves, not through a portal.
Missing your question? Ask us directly — a human replies within one business day.
Your security team wants to vet us? Good.
Send them this page — and send us their questionnaire. We’ll complete it, walk through the architecture on a call with your reviewers, and put the DPA in front of your legal team. The teams that dig deepest end up most comfortable — mechanisms hold up under questioning in a way promises don’t.
