Conversation proposes
AI handles the dialogue — clarifying intent, gathering details, and suggesting next steps.
Security & Trust
NLDONA is designed so AI can help operate the business without becoming the authority over the business. Conversation can propose; NLDONA validates, authorises, and records what actually happens.
Request
Move my appointment.
A product flow — not a padlock illustration.
Access control
Business data is tenant-scoped. People only get the access their membership and role allow — and platform administration is governed separately.
Customer, scheduling, and operations data are held in the business’s own boundary. Cross-tenant access is denied by application policy.
Membership profiles control what operators can read and change. Sensitive operations require the right authorisation — read and write are not the same.
Platform and operator access is separately governed and audited. It is not the same as ordinary tenant membership.
Isolation is enforced by NLDONA’s application security model — not marketed as a separate database for every customer.
Identity & disclosure
Authorisation decides what someone may do. Disclosure rules decide what sensitive information may be shown. Caller or contact context is not automatic proof of identity.
Permission to perform an action does not automatically unlock every piece of customer information. Sensitive details are revealed only when policy allows.
A phone number or email may help locate customer context. It does not by itself prove who is on the line.
When assurance is insufficient, NLDONA can restrict, clarify, or hand off rather than overshare — according to product policy.
Especially important for AI Receptionist: a caller ID does not unlock sensitive records by default.
Account security
Operator accounts use verified email, strong password rules, multi-factor authentication, and session controls before they reach tenant data.
Accounts require email verification. Passwords follow strong length and hashing controls — not stored as recoverable plaintext.
MFA (authenticator app) protects sign-in. Step-up confirmation can be required again for selected sensitive actions — not for every click.
Authenticated sessions can be listed and revoked. Security-sensitive changes can restrict or invalidate access where the product supports it.
MFA strengthens accounts. It does not mean every business action always requires a fresh MFA challenge.
Integrations
Google Calendar, Microsoft Calendar, Gmail, and Google Drive connect through explicit authorisation. Providers inform and deliver; NLDONA keeps business state governed.
Integrations are connected deliberately by authorised users. They are not silently activated from a public page.
Where applicable, NLDONA uses OAuth so access stays scoped to what the business connects — calendars, email workflows, or approved Drive knowledge.
Provider tokens are protected with encrypted storage in NLDONA’s integration architecture. They are not placed in public frontend state.
Busy time constrains availability. Calendar events can be projected outward. Gmail and Drive stay in bounded workflows. Provider events do not silently redefine canonical business state.
Trying NLDONA does not silently turn demo activity into live Production mutations.
Data protection
Public traffic is served over HTTPS. Sensitive credentials and privacy export artifacts use encrypted storage. We do not claim blanket encryption as a slogan.
NLDONA’s public site and product surfaces are designed for HTTPS delivery so data is protected in transit between browser and service.
Integration tokens and selected secrets are protected using encrypted storage server-side — not exposed as business-visible plaintext.
Integrations require explicit connection. Business actions require authorisation. Unsupported mixed authority fails closed. Public demos stay isolated from Production mutation.
We avoid exaggerated security slogans. Claims stay bounded to verified architecture.
Audit & privacy
Operations and security activity help businesses see what happened — without exposing chain-of-thought or raw secrets. Privacy tools cover verified export and customer erasure capabilities.
Operations and Timeline help review actions, handoffs, failures, and important state changes — without hidden reasoning or raw tool arguments.
Account and administrative security operations are recorded for authorised review. This is an audit trail — not marketed as a permanent sealed ledger.
Authorised operators can request organisation and customer data exports. Artifacts are access-controlled, time-limited, and encrypted for download.
Customer erasure follows a governed prepare-and-confirm workflow that de-identifies customer records according to product rules — not an instant ‘delete everything’ button.
General retention-policy products, legal hold, and full organisation/account erasure are not claimed as live capabilities on this page.
NLDONA does not claim SOC 2, ISO, HIPAA, or PCI certification on this page. Formal certifications remain subject to independent audit when earned.
Final Privacy and Terms wording remains subject to published legal pages when they go live.
Answers
Direct answers grounded in current product behaviour — not roadmap marketing.
Business data is tenant-scoped and reached only through authenticated, authorised access. Sensitive actions are governed by NLDONA’s server-side rules. Integration credentials and privacy export artifacts use encrypted storage. Public demos stay isolated from Production mutation.
Yes. Each business operates inside its own tenant boundary. Membership and capability checks enforce access. Cross-tenant access is denied by application policy. NLDONA does not claim a separate database for every customer on this page.
AI can propose actions through conversation. NLDONA validates permissions and business rules before governed actions update business state. Model wording alone is not business authority.
People with membership in the tenant, within the permissions of their role. Authorisation to act and permission to disclose sensitive details are separate decisions.
No. A phone number or similar contact signal may help locate context. It does not by itself prove identity. Sensitive cases can require stronger assurance or human handling.
Yes. Operator accounts support multi-factor authentication with an authenticator app, plus recovery codes. Selected sensitive actions can require step-up confirmation.
Yes. Authenticated sessions can be reviewed and revoked, including broader revoke-all flows where the product supports them.
Connections use explicit OAuth where applicable. Tokens are stored with encrypted credential protection server-side and are not exposed in public frontend state. Connections can be re-authenticated or disconnected when needed.
No. External busy time can constrain availability, and NLDONA bookings can be projected outward as calendar events. Booking truth remains in NLDONA.
Yes. Operational timelines and security-relevant events help authorised users review what NLDONA handled, what failed, and what needs attention. NLDONA does not claim a permanent sealed audit ledger on this page.
No. Operations views are designed to show outcomes and handoffs — not hidden model reasoning, raw provider secrets, or raw tool arguments.
Authorised operators can request organisation and customer exports. Downloads are access-controlled, time-limited, and encrypted. This is not an unrestricted ‘export everything instantly’ button for every dataset.
Customer erasure is available as a governed workflow that de-identifies customer records according to product rules. Full organisation or account erasure is not claimed as a live capability on this page.
NLDONA is designed with GDPR-relevant privacy controls in mind — including export and customer erasure workflows. NLDONA does not claim a ‘GDPR certification’ badge on this page. Formal legal conclusions remain with Privacy/Terms and counsel.
NLDONA does not currently claim SOC 2, ISO 27001, HIPAA, or PCI certification on this page. Security architecture and formal certification are separate.
See it operate
Try NLDONA with isolated demo state, then explore how product surfaces keep authority with your business.
Demo activity does not silently become live Production business actions.