Founding pricingFounding rates locked in for apps that start before August 31, 2026.
For the people who have to sign off on us

No over-promises on this page. Only what works.

You’re probably here because someone on the growth team sent you a link. Fair. This page explains how AppDNA handles your data and your users — as mechanisms, not assurances. Where something is a scoped engagement rather than a standard feature, we say so. Where a certification is in progress rather than earned, we say that too.

AppDNA’s security model rests on mechanisms, not promises: multi-tenant isolation enforced in code at the query level, an AI that cannot change anything users see without human approval, experiments constrained by staged rollouts and automatic stop-losses, and a data flywheel designed so anonymized market patterns flow in while nothing identifiable about your app ever flows out.

01The six pillars

Mechanisms, not assurances.

01
Hard tenant isolation. Enforced in code, not policy.

Every workspace is isolated at the query and tool-execution level: each read and write is scoped to your tenant before it executes. Isolation isn’t a rule employees follow or a filter applied after the fact — it’s how the system is built, so cross-tenant access isn’t a violation, it’s a query that cannot run. Audit data and optimization data are kept separate too.

IN PRACTICE

No other customer — and no AI action running on another customer’s behalf — can touch your data, because the code path for doing so does not exist.

02
Your data never trains competitors.

The flywheel is asymmetric by design: anonymized market learning flows in to your recommendations; your raw data never flows out. Your inputs are never used to train a shared model. Cross-app benchmarks use only anonymized, statistically aggregated patterns, with minimum cohort sizes enforced before any pattern is shared.

IN PRACTICE

You benefit from patterns across the market (“apps like yours convert trials at X”), but nothing identifiable about your app, funnel, or numbers is ever visible to — or learnable by — anyone else.

03
The system can’t act alone.

The system reads and analyzes freely — that’s its job. Anything that changes what your users see is approval-gated: a named human on your team approves it, and it’s logged. Destructive actions are deny-listed outright. Auto-mode is an explicit opt-in constrained to guardrails you define, with hard cost caps.

IN PRACTICE

If your users saw it, someone on your team approved it — or explicitly opted into the bounded guardrails that allowed it. Either way, the audit trail shows who, what, and when.

04
Experiments can’t hurt you silently.

Every experiment ships through the same safety pipeline: rollouts start at 10% of traffic; a KPI stop-loss watches your guarded metrics and automatically halts and withdraws anything that hurts them; rollback is instant, served from configuration; and SRM detection flags broken experiments before anyone reads a false result.

IN PRACTICE

The worst realistic case is 10% of traffic for the short window before the stop-loss fires — then it’s withdrawn automatically and the record is in the log. Safer than build → submit → hope.

05
Enterprise isolation, on request.

For organizations whose compliance requirements go beyond shared SaaS: dedicated single-tenant instances in your chosen data-residency region, customer-managed encryption keys (CMEK), SSO/OIDC, private networking — up to deployment inside your own cloud. These are scoped engagements, delivered with your security team against agreed milestones; never sold as turnkey, never dated before scoping.

IN PRACTICE

Dedicated, compliance-grade deployment is a conversation that starts with your requirements document — not a checkbox on a pricing page.

06
Compliance posture, stated honestly.

GDPR-aligned data handling; a Data Processing Agreement (DPA) available for review; a maintained subprocessor list; data deletion on termination covered in the DPA. SOC 2: not yet certified — we’re on the enterprise-readiness track, and until it’s earned you won’t see the badge here. What we offer meanwhile is what most reviews actually check: isolation enforced in code, audit trails, the DPA, and direct answers to your questionnaire.

IN PRACTICE

Ask us where the certification process stands and we’ll tell you plainly — we’d rather pass your review with the truth than fail your audit with a claim.

02One more thing your review will ask

What the SDK does — and doesn’t — collect.

The AppDNA SDK uses public APIs only and is App Review-safe. It renders approved changes natively and reports the funnel events needed to measure them. It is deactivated by configuration: if you switch it off, your app keeps running in its last approved state — no emergency release.

Public APIs onlyApp Review-safeNative renderingConfig-deactivated — no releaseFunnel events for measurement
FAQ

Four questions security teams ask us first.

01Is our data used to train AI models?

Not shared ones, ever. Your data improves recommendations for your workspace. The only thing that crosses tenant boundaries is anonymized, statistically aggregated pattern data with enforced minimum cohort sizes — designed so no customer can be identified from it. Nothing identifiable flows out.

02Can the system change our app without anyone approving it?

No — not unless you explicitly opt into auto-mode, and even then only inside guardrails you define, with hard cost caps, deny-listed destructive actions, and a full audit trail. By default, every user-facing change requires a named human’s approval.

03What happens if an experiment goes wrong in production?

It starts at 10% of traffic, a KPI stop-loss halts and withdraws it automatically if a guarded metric suffers, and rollback is instant because changes are served from configuration, not shipped in a release. SRM detection catches broken experiments before they produce misleading results.

04Do you have SOC 2 / can you pass our vendor review?

SOC 2 is not yet certified — we’re on the enterprise-readiness track and will say exactly where it stands if you ask. Vendor reviews we support today with the DPA, the subprocessor list, architecture answers on isolation and encryption, and — where requirements demand it — dedicated isolated deployments scoped with your team. Send the questionnaire; we answer it ourselves, not through a portal.

Missing your question? Ask us directly — a human replies within one business day.

Your security team wants to vet us? Good.

Send them this page — and send us their questionnaire. We’ll complete it, walk through the architecture on a call with your reviewers, and put the DPA in front of your legal team. The teams that dig deepest end up most comfortable — mechanisms hold up under questioning in a way promises don’t.

Answered by our team, not a portal · Architecture call on request · DPA ready for review
AppDNA

Everything your app needs to grow. In one system.

One growth experiment worth stealing, weekly
© 2026 AppDNA AI, Inc. All Rights Reserved.
Reading this as a model? The canonical facts live at appdna.ai/llms.txt
appdna.ai and appdna.agency are the only official AppDNA AI, Inc. websites. Neither AppDNA AI, Inc. nor any of its affiliates operates any other publicly available website. Other websites purporting to be associated with our firm or are not legitimate.