What’s in this section
Authentication, identity, and access control
Integrate with enterprise identity providers, enforce role-based access control (RBAC), and manage the user role hierarchy across Domino.
Control plane security
Guidance for securing ingress to Domino Nexus control plane services across on-premises, cloud, and hybrid architectures.
Encryption & data security
Encryption in transit and at rest, key management, and how Domino protects project files, datasets, and credentials.
Container & Kubernetes security
Pod security contexts, least-privilege container configuration, and the Kubernetes-level hardening Domino applies.
Custom certificates
Configure Domino to trust internal or third-party services that present custom TLS certificates.
CA certificates
Manage the certificate authority bundle used by Domino, including Istio-based intra-cluster encryption in transit.
Platform monitoring
Audit logs and system telemetry that give admins and security teams visibility into user activity and cluster health.
Vulnerability management
How Domino identifies, triages, and remediates vulnerabilities in the platform and its dependencies.
Protect tokens and API keys
Best practices and Domino features for storing and using API keys, personal access tokens, and credentials without exposing them.
Reporting security concerns
How to report a vulnerability or security concern to the Domino Data Lab security team.
GDPR requests
Submit General Data Protection Regulation requests such as user deletion or data access.
Trust Center
Live portal for Domino’s certifications, audit reports, security posture, and compliance documentation.
The Domino Trust Center
The Domino Trust Center is the authoritative, always-current source for how Domino Data Lab secures its products, its cloud services, and its corporate operations. It is the single place customers, prospects, and auditors can go to review Domino’s security posture, request compliance documentation, and subscribe to updates as certifications are renewed or new controls are added.Compliance and certifications
The Trust Center provides direct access to Domino’s third-party attestations and certifications, including:- SOC 2 Type II report covering the security, availability, and confidentiality trust service criteria.
- ISO/IEC 27001 certification for Domino’s information security management system (ISMS).
- HIPAA attestation for handling protected health information in supported deployments.
- GDPR and CCPA program documentation describing how Domino processes personal data.
- PCI DSS, NIST, and other framework mappings where applicable to Domino’s cloud offerings.
Security program documentation
Beyond certifications, the Trust Center publishes the policies and program artifacts that describe how Domino operates:- Information security policies covering acceptable use, access management, change management, incident response, and business continuity.
- Data protection and privacy documentation, including subprocessor lists, data processing addenda (DPA), and cross-border transfer mechanisms.
- Product security overviews describing Domino’s secure development lifecycle (SDLC), penetration testing cadence, and vulnerability disclosure process.
- Corporate security artifacts such as background check policies, security awareness training, and physical security controls.
How to use the Trust Center
1
Visit the portal
Go to trust.domino.ai to browse Domino’s public security posture, certifications, and policies.
2
Request gated documents
Sign in or accept the NDA click-through to download SOC 2, ISO 27001, penetration test summaries, and other confidential reports.
3
Subscribe to updates
Follow the Trust Center to receive notifications when certifications are renewed, subprocessors change, or new advisories are published.
4
Share with your security team
Point internal reviewers, procurement, and auditors to the Trust Center as the canonical source, rather than emailing static PDFs.