Security · Deployment
You choose where the data lives
Start on the cloud we operate, or install Damda on your own servers. Either way each customer gets a separate database.
Cloud
RecommendedWe run it, and each customer keeps a separate database
- Your data is separated per customer — we do not mix companies into one table
- We handle the servers, updates, backups, and certificate renewals
- No server on your premises, so rollout is fast
- It scales on the same infrastructure as you grow
The right choice unless something stops data leaving your network.
On-premise
Installed on your own servers
- Data never leaves your internal network
- Deployable into an air-gapped environment
- You decide when updates happen
- Sizing and requirements are agreed with you
For rules that forbid data leaving, or an air-gapped network.
What on-premise needs
One Linux server that can run Docker, and a domain.
- Server
- One Linux server able to run Docker
- Domain
- A DNS A record pointing at that server
- HTTPS
- Certificates are issued and renewed automatically (Let’s Encrypt)
- Database
- PostgreSQL comes up alongside as a container
- Document preview
- An Office-to-PDF converter is included
- Object storage
- Optional — attach S3 or your own object storage
Database, document conversion, web, API, and reverse proxy all come up as containers together. There is nothing to install separately.
Four permission levels
Organisation permissions and project permissions are separate, so the same member can see a different scope in each project.
- Owner
- Members, organisation, projects, and licensing
- Admin
- Organisation and projects (not member management)
- Member
- Manages work inside their own projects
- Guest
- Only invited project channels and DMs — no company announcements or KPIs
What happened stays on the record
Audit log
Successful and failed logins, password changes, permission changes, project and attachment deletions, and unauthorised access attempts are recorded. Ordinary reads are not logged, so the records that matter do not get buried.
Change history
When a task or project changed, who changed it, and what changed.
Approval history
Opening, submitting, confirming, rejecting, and reopening a KPI, each with its reason.
You choose where the data lives
Every deployment gives each customer a separate database. If data cannot leave your premises, choose on-premise.
Choose your deployment
Use the cloud we operate (Demo, Standard, Professional) or install Damda on your own servers (Enterprise).
Separate databases
Every deployment gives each customer its own database. We do not mix several companies into one table, so a mistaken query cannot expose another company’s data.
On-premise
Deployed to your own servers with Docker. Data never leaves the company.
Four permission levels
Owner, admin, member, guest — with access scoped per project.
Audit log
Logins, permission changes, data deletions, and attachment access are recorded across about twenty event types.
Guest expiry
Give an external collaborator 1, 7, or 14 days of access — 1 day if nothing is chosen. When it passes they can no longer sign in, and a day before that they are warned so they can request an extension.
Automatic HTTPS
Certificates are issued and renewed automatically with Caddy and Let’s Encrypt.
Authenticated downloads
Attachments and company files cannot be fetched with a link alone. Permission is checked before anything is served.
Session handling
Access tokens last 15 minutes, refresh tokens 7 days. Sign-in attempts are limited.
Two-factor authentication
A second check through an authenticator app on top of the password. Owners and admins must enrol before they can sign in — the most privileged accounts are not left to choose.
SSO sign-in
Coming soonSign in with your corporate account. SAML is planned for Professional and Enterprise — it is in the plan, the implementation is not there yet.
Information security certifications
See Damda set up the way your team works
A 30-minute demo covers the real screens and how a rollout actually goes.