Skip to main content
Domino is designed to give enterprise teams a platform they can trust with sensitive data, models, and intellectual property. Security is layered across the platform: identity and access, network and control plane, container and Kubernetes hardening, encryption, monitoring, and vulnerability management, all backed by a formal quality & compliance program that is continuously attested to in the Domino Trust Center. This page summarizes what the Security & Compliance section covers and takes a deeper look at what the Trust Center provides.

What’s in this section

Authentication, identity, and access control

Integrate with enterprise identity providers, enforce role-based access control (RBAC), and manage the user role hierarchy across Domino.

Control plane security

Guidance for securing ingress to Domino Nexus control plane services across on-premises, cloud, and hybrid architectures.

Encryption & data security

Encryption in transit and at rest, key management, and how Domino protects project files, datasets, and credentials.

Container & Kubernetes security

Pod security contexts, least-privilege container configuration, and the Kubernetes-level hardening Domino applies.

Custom certificates

Configure Domino to trust internal or third-party services that present custom TLS certificates.

CA certificates

Manage the certificate authority bundle used by Domino, including Istio-based intra-cluster encryption in transit.

Platform monitoring

Audit logs and system telemetry that give admins and security teams visibility into user activity and cluster health.

Vulnerability management

How Domino identifies, triages, and remediates vulnerabilities in the platform and its dependencies.

Protect tokens and API keys

Best practices and Domino features for storing and using API keys, personal access tokens, and credentials without exposing them.

Reporting security concerns

How to report a vulnerability or security concern to the Domino Data Lab security team.

GDPR requests

Submit General Data Protection Regulation requests such as user deletion or data access.

Trust Center

Live portal for Domino’s certifications, audit reports, security posture, and compliance documentation.

The Domino Trust Center

The Domino Trust Center is the authoritative, always-current source for how Domino Data Lab secures its products, its cloud services, and its corporate operations. It is the single place customers, prospects, and auditors can go to review Domino’s security posture, request compliance documentation, and subscribe to updates as certifications are renewed or new controls are added.

Compliance and certifications

The Trust Center provides direct access to Domino’s third-party attestations and certifications, including:
  • SOC 2 Type II report covering the security, availability, and confidentiality trust service criteria.
  • ISO/IEC 27001 certification for Domino’s information security management system (ISMS).
  • HIPAA attestation for handling protected health information in supported deployments.
  • GDPR and CCPA program documentation describing how Domino processes personal data.
  • PCI DSS, NIST, and other framework mappings where applicable to Domino’s cloud offerings.
Reports and letters can be requested directly from the Trust Center, typically gated by an NDA click-through, so account teams and prospects can obtain them without a manual back-and-forth.

Security program documentation

Beyond certifications, the Trust Center publishes the policies and program artifacts that describe how Domino operates:
  • Information security policies covering acceptable use, access management, change management, incident response, and business continuity.
  • Data protection and privacy documentation, including subprocessor lists, data processing addenda (DPA), and cross-border transfer mechanisms.
  • Product security overviews describing Domino’s secure development lifecycle (SDLC), penetration testing cadence, and vulnerability disclosure process.
  • Corporate security artifacts such as background check policies, security awareness training, and physical security controls.

How to use the Trust Center

1

Visit the portal

Go to trust.domino.ai to browse Domino’s public security posture, certifications, and policies.
2

Request gated documents

Sign in or accept the NDA click-through to download SOC 2, ISO 27001, penetration test summaries, and other confidential reports.
3

Subscribe to updates

Follow the Trust Center to receive notifications when certifications are renewed, subprocessors change, or new advisories are published.
4

Share with your security team

Point internal reviewers, procurement, and auditors to the Trust Center as the canonical source, rather than emailing static PDFs.
Last modified on August 11, 2026