How Demiton handles your data
Credentials never rest on disk in plaintext. Operational data rests in Azure Australia East. Two things leave it during processing, and they are named on this page rather than hidden: model inference, and Exa web search.
Aligned means the certification is not done yet. The honest word for that is aligned.
Three things we can say out loud
Not a pledge. A description of where the data actually is.
Australian data residency
Operational data rests in Azure Australia East (Sydney). Two things leave it during processing, and both are named:
- Model inference: Azure OpenAI
- Web search: Exa
AES-256 at rest
Data at rest is encrypted with AES-256. In transit we enforce TLS 1.3.
- Envelope encryption
- Automated key rotation
Secrets out of the database
Integration secrets are never stored in the application database. They are isolated in hardware-backed Azure Key Vault.
- Azure Key Vault integration
- Just-in-time access
Credentials never rest on disk
Most integration platforms write credentials to temporary disks while they work. If that server is compromised, those secrets are exposed.
Demiton keeps a credential in memory only, for the life of one handshake:
- Ingestion - The credential is pulled into an ephemeral RAM buffer.
- Use - It authenticates the call, and nothing more.
- Closure - The buffer is zeroed and the audit line is written.
Your registers do not live in RAM. They persist, encrypted at rest. It is the secrets that never do.
Transform.Align.Encrypt()Secrets in RAM only
Technical Controls
For the person who has to sign off on it.
For certifications, data residency, retention and audit posture, see Security & Compliance.
| Control Area | Implementation |
|---|---|
| Application Security | Static analysis (Bandit SAST), secret scanning (trufflehog), and dynamic analysis (OWASP ZAP DAST). |
| Access Control (RBAC) | Multi-factor authentication enforced. Role-based access tied to Microsoft Entra ID. |
| Network Security | Azure Virtual Network, Private Link, and strict egress allow-listing for integration endpoints. |
| Audit Logging | Immutable logs of every transaction attempt, IP address, and outcome. Retained in cold storage. |
| Disaster Recovery | Backups in Azure Australia East. |
Responsible Disclosure
If you find a vulnerability, tell us at support@demiton.io. We triage every report and respond.
Two processing exceptions leave Australia, and they are the only two: model inference on Azure OpenAI, and Exa web search. If you need the residency position in writing for a procurement team, ask for the whitepaper.
Common questions
Where does Demiton store my data?
Operational data rests in Microsoft Azure Australia East (Sydney). Two things leave it during processing: model inference runs on Azure OpenAI, and Exa web search leaves by design. Those are the only two, and they are named here rather than hidden in a footnote.
How does Demiton encrypt my data?
At rest, AES-256. In transit, TLS 1.3. Integration secrets sit in hardware-backed Azure Key Vault with automated key rotation.
Does Demiton store my integration credentials on disk?
No. Credentials are pulled from source systems into an ephemeral RAM buffer, used for the operation, and then zeroed out. They are never written to disk in plaintext.
What authentication does Demiton use?
Microsoft Entra ID (OIDC), with multi-factor authentication enforced. Every action traces to a named person and lands in an append-only audit trail.
How do I report a security vulnerability?
Email support@demiton.io. We triage every report and respond.