Security and data

Clear commitments. No borrowed badges.

goodDingo is in a founding beta. This page separates the controls that can be inspected now from the production decisions that must be documented before an organization goes live.

Last reviewed July 27, 2026

Data ownership

Your organization’s records remain yours. goodDingo’s product promise includes self-serve export to plain CSV files without an export fee.

Responsible disclosure

Report a suspected security issue privately to support@gooddingo.com. Do not include live customer data in the first message.

Honest beta posture

goodDingo does not claim SOC 2, HIPAA, PCI, or other certifications on this site. Any future claim should link to current evidence and scope.

Current baseline

What is implemented and inspectable now.

Current

Hardened public site

The marketing site is served over HTTPS through Cloudflare Pages, uses local images and fonts, and ships a content security policy and browser security headers.

Current

No ad tracking

No advertising pixels, marketing cookies, or third-party analytics are included in the published marketing build.

Built in beta

Scoped roles and audit events

The application code implements role-based authorization and audit events for protected workflows. These controls still require deployment-specific verification.

Product commitment

Portable records

Organization records are designed to remain organization-scoped and exportable as plain CSV files without an export charge.