Skip to content
DGxOne Trust Architecture Open DGxOne

Trust & Security

Trust before every execution.

Before external reasoning begins, DGxOne evaluates the request, identifies sensitive information, applies handling policy, and determines whether an external provider is permitted.

01

How Your Information Moves

A request follows defined controls before reaching an AI provider.

DGxOne does not treat every request the same. Handling depends on the information detected, workspace policy, provider availability, and the authorization decision.

  1. 01 You ask DGxOne

    The request enters the authenticated workspace context.

  2. 02 Trust evaluation

    Sensitive fields and handling requirements are evaluated.

  3. 03 Context authorization

    Relevant knowledge and approved memory are selected within the authorized scope.

  4. 04 Provider decision

    DGxOne selects local handling or an approved external reasoning provider.

  5. 05 Response or mission

    The result returns to DGx Command or continues in Mission Control.

02

What DGxOne Protects

Your workspace remains the center of the intelligence.

Workspace

Conversations and activity

Conversations and operational history remain associated with the authorized user and workspace rather than a temporary browser identity.

Knowledge

Documents and retrieved context

Uploaded information is retrieved only when relevant and should remain scoped to its authorized workspace.

Memory

Long-term personal context

Persistent memory is governed separately from temporary conversation context and should follow the user’s configured memory policy.

Providers

External reasoning access

External models receive bounded context only after the active trust decision permits that route.

03

Active Controls

Security is implemented as system behavior—not a marketing label.

Trust evaluation Before provider execution

Requests are evaluated before external reasoning is authorized.

Sensitive-field detection Classification and redaction

Defined sensitive patterns can trigger redaction, approval requirements, or local-only handling.

Provider governance Approved execution routes

Provider execution follows the trust decision and configured provider availability.

Credential isolation Server-managed configuration

Current provider credentials are managed through the server environment rather than exposed in browser storage.

Provider independence DGxOne-owned intelligence

Knowledge, memory, evidence, orchestration, and mission history remain separate from the selected reasoning provider.

Evidence identity Source-aware outcomes

Retrieved evidence can preserve document identity, citations, source location, and confidence metadata.

04

Security Boundaries

Clear status is more trustworthy than unsupported claims.

DGxOne does not claim certifications or controls that have not been independently validated.

Active foundation

Implemented architecture

  • Trust evaluation before provider use
  • Redaction and local-only routing paths
  • Environment-managed provider credentials
  • Knowledge and evidence contracts
  • Provider-independent intelligence ownership
In development

Production identity and governance

  • Complete authenticated multi-user isolation
  • Onboarding-backed privacy preferences
  • Organization-level access policies
  • Administrative audit visibility
  • Retention and deletion workflows
Future enterprise controls

Advanced deployment options

  • Enterprise SSO and passkeys
  • Customer-managed encryption keys
  • Expanded audit and compliance exports
  • Deployment-specific retention enforcement
  • Independent certification programs

05

Plain-Language Answers

What users should understand before trusting DGxOne.

Does DGxOne automatically remember everything?

No. Temporary conversation context and persistent memory are separate concepts. Long-term memory should follow the user’s configured memory policy and approval preferences.

Can sensitive information be prevented from reaching an external provider?

DGxOne includes trust evaluation, redaction, blocked, and local-only routing paths. Final protection also depends on deployment configuration and the active organizational policy.

Does an external model become the owner of my workspace intelligence?

No. DGxOne is designed to retain ownership of the workspace intelligence layer. External providers serve as interchangeable reasoning engines.

Is DGxOne currently certified for regulated data?

Certification depends on deployment, infrastructure, contractual controls, independent audits, and the applicable regulatory framework. This page does not claim SOC 2, HIPAA, FedRAMP, or other certification unless formally achieved and documented.

Do external AI providers have their own data policies?

Yes. Provider retention and processing terms depend on the provider account, API agreement, and selected service configuration. Organizations must review those terms as part of deployment approval.

Continue Exploring

Understand how DGxOne separates intelligence from external reasoning.