Security
Last updated: July 2026
At Day1, protecting customer data is one of our highest priorities. We understand that organizations trust us with their business information, documents, and AI-powered workflows.
We are committed to implementing practical and industry-standard security measures designed to safeguard your data and maintain the reliability of our platform. While no online service can guarantee absolute security, we continuously work to improve our systems and follow security best practices throughout our platform.
Our Security Principles
Our approach to security is guided by four core principles:
- Protect customer data.
- Minimize access to sensitive information.
- Build secure systems by design.
- Continuously improve our security posture.
Data Encryption
We use encryption to help protect customer information.
Data in Transit
All communication between your browser, applications, and Day1 is encrypted using HTTPS with Transport Layer Security (TLS). This helps protect information from interception while it is transmitted across the internet.
Data at Rest
Customer data stored within our infrastructure is protected using encryption mechanisms provided by our cloud infrastructure providers where applicable.
Authentication & Access Control
Day1 provides secure authentication mechanisms designed to protect user accounts.
Supported authentication methods may include:
- Email and password
- Google Sign-In (OAuth)
- Organization-based authentication
- Future enterprise SSO support
Access to workspaces is permission-based and managed by organization administrators.
Workspace Isolation
Day1 is a multi-tenant platform.
Each organization's workspace is logically separated from other organizations to help ensure customer data remains isolated.
Workspace members can only access information they have been granted permission to view.
Infrastructure Security
Our platform is hosted using reputable cloud infrastructure providers designed to deliver secure, scalable, and reliable services.
Infrastructure security includes measures such as:
- Network protection
- Secure cloud environments
- Firewall configurations
- Availability monitoring
- Automated infrastructure management
AI Security
AI features are a core part of Day1.
Customer content submitted to AI-powered features is processed solely to provide the requested functionality, such as:
- Knowledge retrieval
- Sales simulations
- AI coaching
- Content generation
- Search
- Summarization
We do not sell customer prompts, uploaded documents, or AI conversations.
Organizations retain ownership of their content.
Data Privacy
Day1 is designed to collect only the information necessary to provide our Services.
We do not sell customer data to advertisers or third parties.
Our collection, processing, and storage of personal information is described in our Privacy Policy.
Access Management
Access to customer information is limited to authorized personnel when necessary for:
- Platform operations
- Technical support
- Troubleshooting
- Security investigations
Access is provided only when required and follows internal operational procedures.
Monitoring & Reliability
We monitor the health and performance of our systems to maintain service reliability and identify potential operational issues.
Monitoring may include:
- Application health
- Error tracking
- Performance metrics
- Availability monitoring
- Operational logging
Backups & Recovery
We implement backup and recovery processes designed to help protect customer data against accidental loss or service disruption.
Recovery procedures are regularly reviewed and improved as our platform evolves.
Responsible Disclosure
We appreciate responsible security research.
If you believe you have discovered a security vulnerability affecting Day1, please report it to us privately.
Security Contact
Email: security@day1.ai
Please include:
- Description of the issue
- Steps to reproduce
- Potential impact
- Supporting screenshots or evidence if available
We ask that researchers avoid accessing customer data, disrupting services, or publicly disclosing vulnerabilities before they have been addressed.
Third-Party Services
Day1 integrates with trusted third-party providers to deliver certain platform functionality, including authentication, cloud hosting, AI services, and communications. These providers maintain their own security and privacy practices.
Security Roadmap
As Day1 continues to grow, we are committed to strengthening our security program.
Areas under continuous improvement include:
- Enhanced monitoring and alerting
- Expanded access controls
- Enterprise authentication options
- Security reviews and testing
- Infrastructure hardening
- Additional compliance and governance initiatives
Shared Responsibility
Security is a shared responsibility.
We encourage customers to:
- Use strong passwords.
- Enable secure authentication methods where available.
- Manage workspace permissions carefully.
- Review member access regularly.
- Protect devices used to access Day1.