How DNA protects client data
Understand where your client data lives, who can access it, and how DNA handles security and privacy.
Last updated
Introduction
This page explains how DNA handles the client information you put into the product: where it lives, how it is protected, and who has access to it. Use it to answer compliance questions from your firm or regulators, or just to get a clear picture of what happens behind the scenes.
Where your data lives
DNA stores every piece of client data you enter in Microsoft Azure’s Canada East region. That includes:
- Client profiles and their basic details.
- Every asset, debt, beneficiary, and coverage record.
- Every note and document you upload.
- Every needs analysis you run.
Stored client data is not replicated outside Canada. AI processing is the one exception to the Canadian boundary, and it is covered in its own section below.
Encryption in transit and at rest
DNA encrypts data in two places:
- In transit: every connection between your browser and DNA uses HTTPS, so data is encrypted on the wire.
- At rest: the database and file storage behind DNA use Azure’s built-in encryption, so stored data is encrypted as well.
How AI processing works
Helix, document extraction, the needs analysis, and compliance document generation all send content to an AI model to get a result back. That runs on Microsoft Azure AI Foundry, using models from OpenAI and Anthropic, deployed in a United States processing region. What that means in practice:
- Your data is stored in Canada. What crosses the border is the content needed for a given request, which is processed and returned.
- The result comes back and is stored in Canada with the rest of your client’s record.
- Your data is never used to train or fine-tune AI models. That applies to DNA and, by contract, to the AI providers we use.
- Processing happens only in Canada and the United States, never in any other country. If we change which model we use, the replacement runs in the United States on the same terms.
- While content is being processed in the United States it is subject to United States law, and may be available to government authorities there under lawful orders. Information held in Canada is subject to Canadian legal process in the same way. We say this plainly rather than leave it out.
DNA’s privacy policy sets this out in full: see the AI Processing and Data Residency sections of the privacy policy.
Who can see what
Access to client data follows your plan’s structure:
- Starter and Pro: you are the only advisor who can see the client files on your account.
- Team: every active team member can see every client file in the workspace. There is no per-client access restriction beyond team membership.
- DNA staff: a small number of DNA employees can access production systems for support and operations. DNA logs every staff access and governs it under our internal policies.
Invited-but-not-yet-joined advisors cannot see any client data until they accept the invite and complete sign-in.
Authentication
DNA uses WorkOS, a specialist identity provider, to handle all sign-ins. WorkOS manages password storage, reset flows, and the sign-in form itself. DNA never stores your password.
Getting a copy of your data, or deleting it
An organization administrator can delete the organization and everything in it from the team settings. Deletion takes effect after a 30-day grace period and can be cancelled during it. When it runs, client records, uploaded documents, and Helix conversation history are permanently erased, including the stored files themselves.
DNA does not currently have self-serve data export. If you need a copy of your data, email support@dynamicneedsanalysis.com. The team will confirm your identity, process the request, and send back the data.