Security & Privacy
Your data is yours. Your customers' data is yours. Deway is built to enhance your product capabilities without compromising privacy.
What is Deway?
Deway is an AI-powered product intelligence platform that helps SaaS products become self-aware. We observe how users interact with your product, detect misconfigurations and friction, and provide intelligent guidance to ensure customers use your product correctly.
Our mission is simple: make your product smarter and your customers more successful, while respecting privacy every step of the way.
Privacy Settings & Control
You decide what Deway observes
Choose which user interactions, events, and data Deway can monitor. Everything is opt-in, and you can pause or disable monitoring at any time.
- Event-level permissions
- Domain whitelisting/blacklisting
- One-click pause/resume
Zero data retention policy
For Enterprise customers, we offer a zero data retention policy. Your data is processed in real-time and never stored on our servers.
Note: Standard plans include 30-day data retention for improved intelligence. You can request deletion at any time.
Data
You own your data
Everything Deway learns about your product and users belongs to you. We're simply custodians helping your customers succeed.
Export anytime Download all your data in standard formats (JSON, CSV)
Delete permanently Request full account deletion and we'll remove everything
No third-party sharing Your data is never sold, shared, or used for advertising
Encryption standards
In transit
All data transmitted using TLS 1.3 with perfect forward secrecy
At rest
Data encrypted using AES-256-GCM with regular key rotation
Authentication
Secure access
Multi-factor authentication Required for all accounts
Passkey support Passwordless authentication with WebAuthn
Session management View and revoke active sessions
Enterprise authentication
SAML 2.0 SSO Integrate with your identity provider
SCIM provisioning Automated user lifecycle management
IP allowlisting Restrict access to approved networks
Compliance
SOC 2 Type II In progress — Annual third-party security audits
GDPR Compliant — Full compliance with EU data protection
HIPAA Available on request — BAA available for Enterprise plans
Infrastructure
Hosted on Google Cloud Platform
We leverage GCP's world-class security infrastructure to protect your data.
- ISO 27001/27017/27018 certified
- 99.95% uptime SLA
- Automatic failover and redundancy
Regional data residency
Choose where your data is stored during account setup.
US — United States (us-central1, Iowa) EU — European Union (europe-west1, Belgium)
Security Contact
Have a security concern? Found a vulnerability? Questions about our practices?
security@deway.ai
We aim to respond to all security inquiries within 24 hours.
Last updated: January 2025
© 2025 Deway. All rights reserved.