Skip to content

Security & Trust

AI that can act — without taking control away from your business.

NLDONA is designed so AI can help operate the business without becoming the authority over the business. Conversation can propose; NLDONA validates, authorises, and records what actually happens.

Request

Move my appointment.

  1. Identity / accessAllowed context
  2. Business rulesAvailability & permissions checked
  3. Governed actionAppointment rescheduled
  4. Audit / outcomeVisible result recorded
  • Authorised
  • Policy checked
  • Business state updated
  • Activity recorded

A product flow — not a padlock illustration.

Business authority

AI can help make things happen. It does not become the source of truth.

Conversations may propose actions. NLDONA applies permissions and business rules before anything becomes a booking, customer, or payment fact.

Conversation proposes

AI handles the dialogue — clarifying intent, gathering details, and suggesting next steps.

NLDONA decides what is allowed

Authorisation, disclosure rules, and business constraints are applied before a sensitive action completes.

Business state stays governed

Canonical business records remain server-owned. Model text does not silently become a booking, customer, or payment fact.

AI says a slot is available

Availability is confirmed by NLDONA’s scheduling rules — not by model wording alone.

AI says a payment succeeded

Payment status comes from the governed payment path — not from chat phrasing.

A provider sends an event

External events provide context or delivery. They do not automatically redefine business truth.

AI owns conversation. NLDONA owns business authority.

Access control

Each business operates inside its own security boundary.

Business data is tenant-scoped. People only get the access their membership and role allow — and platform administration is governed separately.

Tenant-scoped data

Customer, scheduling, and operations data are held in the business’s own boundary. Cross-tenant access is denied by application policy.

Roles and permissions

Membership profiles control what operators can read and change. Sensitive operations require the right authorisation — read and write are not the same.

Separate platform administration

Platform and operator access is separately governed and audited. It is not the same as ordinary tenant membership.

Isolation is enforced by NLDONA’s application security model — not marketed as a separate database for every customer.

Identity & disclosure

Being allowed to act is not the same as revealing every detail.

Authorisation decides what someone may do. Disclosure rules decide what sensitive information may be shown. Caller or contact context is not automatic proof of identity.

Authorisation ≠ disclosure

Permission to perform an action does not automatically unlock every piece of customer information. Sensitive details are revealed only when policy allows.

Contact context ≠ verified identity

A phone number or email may help locate customer context. It does not by itself prove who is on the line.

Ambiguous cases stay cautious

When assurance is insufficient, NLDONA can restrict, clarify, or hand off rather than overshare — according to product policy.

Especially important for AI Receptionist: a caller ID does not unlock sensitive records by default.

Account security

Protect the account before it reaches business data.

Operator accounts use verified email, strong password rules, multi-factor authentication, and session controls before they reach tenant data.

Email verification & passwords

Accounts require email verification. Passwords follow strong length and hashing controls — not stored as recoverable plaintext.

Multi-factor authentication

MFA (authenticator app) protects sign-in. Step-up confirmation can be required again for selected sensitive actions — not for every click.

Sessions you can revoke

Authenticated sessions can be listed and revoked. Security-sensitive changes can restrict or invalidate access where the product supports it.

MFA strengthens accounts. It does not mean every business action always requires a fresh MFA challenge.

Integrations

Connected apps stay connected — without becoming business authority.

Google Calendar, Microsoft Calendar, Gmail, and Google Drive connect through explicit authorisation. Providers inform and deliver; NLDONA keeps business state governed.

Explicit connection

Integrations are connected deliberately by authorised users. They are not silently activated from a public page.

OAuth and scoped access

Where applicable, NLDONA uses OAuth so access stays scoped to what the business connects — calendars, email workflows, or approved Drive knowledge.

Credentials stay server-side

Provider tokens are protected with encrypted storage in NLDONA’s integration architecture. They are not placed in public frontend state.

Provider boundary

Busy time constrains availability. Calendar events can be projected outward. Gmail and Drive stay in bounded workflows. Provider events do not silently redefine canonical business state.

Trying NLDONA does not silently turn demo activity into live Production mutations.

Data protection

Protect what matters — with honest scope.

Public traffic is served over HTTPS. Sensitive credentials and privacy export artifacts use encrypted storage. We do not claim blanket encryption as a slogan.

In transit

NLDONA’s public site and product surfaces are designed for HTTPS delivery so data is protected in transit between browser and service.

Sensitive credentials

Integration tokens and selected secrets are protected using encrypted storage server-side — not exposed as business-visible plaintext.

Safe defaults that are real

Integrations require explicit connection. Business actions require authorisation. Unsupported mixed authority fails closed. Public demos stay isolated from Production mutation.

We avoid exaggerated security slogans. Claims stay bounded to verified architecture.

Audit & privacy

Important activity leaves a trail. Privacy controls stay scoped.

Operations and security activity help businesses see what happened — without exposing chain-of-thought or raw secrets. Privacy tools cover verified export and customer erasure capabilities.

What stays visible

Operational history

Operations and Timeline help review actions, handoffs, failures, and important state changes — without hidden reasoning or raw tool arguments.

Security-relevant events

Account and administrative security operations are recorded for authorised review. This is an audit trail — not marketed as a permanent sealed ledger.

Privacy capabilities available today

Organisation and customer export

Authorised operators can request organisation and customer data exports. Artifacts are access-controlled, time-limited, and encrypted for download.

Customer erasure workflow

Customer erasure follows a governed prepare-and-confirm workflow that de-identifies customer records according to product rules — not an instant ‘delete everything’ button.

Honest limits

General retention-policy products, legal hold, and full organisation/account erasure are not claimed as live capabilities on this page.

Clear about what we do not claim

  • No fake compliance badges on this page
  • Caller ID does not prove customer identity
  • Providers are not treated as business authority
  • AI does not become hidden clinical or legal authority
  • Security architecture is not the same as formal certification

NLDONA does not claim SOC 2, ISO, HIPAA, or PCI certification on this page. Formal certifications remain subject to independent audit when earned.

Final Privacy and Terms wording remains subject to published legal pages when they go live.

Answers

Security questions buyers actually ask.

Direct answers grounded in current product behaviour — not roadmap marketing.

How does NLDONA protect business data?

Business data is tenant-scoped and reached only through authenticated, authorised access. Sensitive actions are governed by NLDONA’s server-side rules. Integration credentials and privacy export artifacts use encrypted storage. Public demos stay isolated from Production mutation.

Is each business’s data separated?

Yes. Each business operates inside its own tenant boundary. Membership and capability checks enforce access. Cross-tenant access is denied by application policy. NLDONA does not claim a separate database for every customer on this page.

Can AI change business data directly?

AI can propose actions through conversation. NLDONA validates permissions and business rules before governed actions update business state. Model wording alone is not business authority.

Who can access customer information?

People with membership in the tenant, within the permissions of their role. Authorisation to act and permission to disclose sensitive details are separate decisions.

Does caller ID verify a customer?

No. A phone number or similar contact signal may help locate context. It does not by itself prove identity. Sensitive cases can require stronger assurance or human handling.

Does NLDONA support MFA?

Yes. Operator accounts support multi-factor authentication with an authenticator app, plus recovery codes. Selected sensitive actions can require step-up confirmation.

Can sessions be revoked?

Yes. Authenticated sessions can be reviewed and revoked, including broader revoke-all flows where the product supports them.

How are Google and Microsoft connections protected?

Connections use explicit OAuth where applicable. Tokens are stored with encrypted credential protection server-side and are not exposed in public frontend state. Connections can be re-authenticated or disconnected when needed.

Does Google Calendar become the source of truth?

No. External busy time can constrain availability, and NLDONA bookings can be projected outward as calendar events. Booking truth remains in NLDONA.

Can NLDONA audit what happened?

Yes. Operational timelines and security-relevant events help authorised users review what NLDONA handled, what failed, and what needs attention. NLDONA does not claim a permanent sealed audit ledger on this page.

Does NLDONA expose AI chain-of-thought?

No. Operations views are designed to show outcomes and handoffs — not hidden model reasoning, raw provider secrets, or raw tool arguments.

Can I export my data?

Authorised operators can request organisation and customer exports. Downloads are access-controlled, time-limited, and encrypted. This is not an unrestricted ‘export everything instantly’ button for every dataset.

Can data be deleted?

Customer erasure is available as a governed workflow that de-identifies customer records according to product rules. Full organisation or account erasure is not claimed as a live capability on this page.

Is NLDONA GDPR compliant / certified?

NLDONA is designed with GDPR-relevant privacy controls in mind — including export and customer erasure workflows. NLDONA does not claim a ‘GDPR certification’ badge on this page. Formal legal conclusions remain with Privacy/Terms and counsel.

Does NLDONA currently claim SOC 2, ISO 27001, or HIPAA certification?

NLDONA does not currently claim SOC 2, ISO 27001, HIPAA, or PCI certification on this page. Security architecture and formal certification are separate.

See it operate

See NLDONA operate with your business rules — before you go live.

Try NLDONA with isolated demo state, then explore how product surfaces keep authority with your business.

Demo activity does not silently become live Production business actions.