Skip to content

Security · Deployment

You choose where the data lives

Start on the cloud we operate, or install Damda on your own servers. Either way each customer gets a separate database.

Cloud

Recommended

We run it, and each customer keeps a separate database

  • Your data is separated per customer — we do not mix companies into one table
  • We handle the servers, updates, backups, and certificate renewals
  • No server on your premises, so rollout is fast
  • It scales on the same infrastructure as you grow

The right choice unless something stops data leaving your network.

On-premise

Installed on your own servers

  • Data never leaves your internal network
  • Deployable into an air-gapped environment
  • You decide when updates happen
  • Sizing and requirements are agreed with you

For rules that forbid data leaving, or an air-gapped network.

What on-premise needs

One Linux server that can run Docker, and a domain.

Server
One Linux server able to run Docker
Domain
A DNS A record pointing at that server
HTTPS
Certificates are issued and renewed automatically (Let’s Encrypt)
Database
PostgreSQL comes up alongside as a container
Document preview
An Office-to-PDF converter is included
Object storage
Optional — attach S3 or your own object storage

Database, document conversion, web, API, and reverse proxy all come up as containers together. There is nothing to install separately.

Four permission levels

Organisation permissions and project permissions are separate, so the same member can see a different scope in each project.

Owner
Members, organisation, projects, and licensing
Admin
Organisation and projects (not member management)
Member
Manages work inside their own projects
Guest
Only invited project channels and DMs — no company announcements or KPIs

What happened stays on the record

Audit log

Successful and failed logins, password changes, permission changes, project and attachment deletions, and unauthorised access attempts are recorded. Ordinary reads are not logged, so the records that matter do not get buried.

Change history

When a task or project changed, who changed it, and what changed.

Approval history

Opening, submitting, confirming, rejecting, and reopening a KPI, each with its reason.

You choose where the data lives

Every deployment gives each customer a separate database. If data cannot leave your premises, choose on-premise.

Choose your deployment

Use the cloud we operate (Demo, Standard, Professional) or install Damda on your own servers (Enterprise).

Separate databases

Every deployment gives each customer its own database. We do not mix several companies into one table, so a mistaken query cannot expose another company’s data.

On-premise

Deployed to your own servers with Docker. Data never leaves the company.

Four permission levels

Owner, admin, member, guest — with access scoped per project.

Audit log

Logins, permission changes, data deletions, and attachment access are recorded across about twenty event types.

Guest expiry

Give an external collaborator 1, 7, or 14 days of access — 1 day if nothing is chosen. When it passes they can no longer sign in, and a day before that they are warned so they can request an extension.

Automatic HTTPS

Certificates are issued and renewed automatically with Caddy and Let’s Encrypt.

Authenticated downloads

Attachments and company files cannot be fetched with a link alone. Permission is checked before anything is served.

Session handling

Access tokens last 15 minutes, refresh tokens 7 days. Sign-in attempts are limited.

Two-factor authentication

A second check through an authenticator app on top of the password. Owners and admins must enrol before they can sign in — the most privileged accounts are not left to choose.

SSO sign-in

Coming soon

Sign in with your corporate account. SAML is planned for Professional and Enterprise — it is in the plan, the implementation is not there yet.

Information security certifications

ISO 27001In progressISMS-PIn progress

See Damda set up the way your team works

A 30-minute demo covers the real screens and how a rollout actually goes.