Live

DodoDesk is here modern ITSM for teams and MSPs.

Sign up free

Security

Your data is safe with DodoBay.

Security is not a feature we added later it is built into every layer of the DodoBay platform from day one.

TLS 1.2/1.3

In transit

bcrypt

Password hashing

MFA / SSO

TOTP + SAML 2.0

99.9%

Uptime SLA

Platform Security

Strong defaults at the edge.

Encryption in transit and at rest

All data transmitted between your browser and DodoBay servers is encrypted using TLS 1.2/1.3. Passwords are hashed using bcrypt and are never stored in plain text.

Multi-Factor Authentication (MFA)

All DodoBay products support MFA via time-based one-time passwords (TOTP). Administrators can enforce MFA across their entire organisation as a policy requirement.

Single Sign-On (SSO)

DodoBay supports enterprise SSO via Google Workspace, Microsoft Entra (Azure AD), Okta, and any SAML 2.0 compatible identity provider.

IP Whitelisting

Enterprise plan customers can restrict access to DodoBay to specific IP addresses or CIDR ranges.

Data Isolation & Multi-Tenancy

Your data stays yours.

Complete tenant isolation

Every customer's data is logically isolated at the database level. No customer can access another customer's data under any circumstances. This applies to tickets, assets, users, reports, and all platform content.

MSP data separation

Managed Service Providers using DodoBay to manage multiple client organisations benefit from strict client-level data isolation. Each client's data remains entirely separate even when managed by the same MSP account.

Role-based access control

DodoBay enforces a five-tier role hierarchy Employee, Agent, Admin, Super Admin, and Platform Admin ensuring every user sees only the data they are authorised to access.

Audit & Compliance

Provable, principled, private.

Full audit log

Every action taken within DodoBay ticket updates, user changes, configuration modifications, login events is recorded in a tamper-evident audit log with timestamp, user identity, and IP address. Audit logs are available to administrators at all times.

Data retention and deletion

Customer data is retained for the duration of the subscription. Upon termination, data is available for export and is permanently deleted upon request in accordance with our data retention policy.

Mauritius Data Protection Act 2017

DodoBay Company Limited operates in compliance with the Mauritius Data Protection Act 2017 and is registered with the Data Protection Office of Mauritius. We uphold your rights to access, correct, and request deletion of your personal data.

GDPR-aligned practices

While DodoBay is headquartered in Mauritius, we follow GDPR-aligned data protection principles including data minimisation, purpose limitation, and the right to erasure giving our customers across Africa, Europe, and beyond confidence in how their data is handled.

Infrastructure Security

Enterprise-grade, edge-protected.

Cloud-native infrastructure

DodoBay runs on enterprise-grade cloud infrastructure with automatic failover, daily backups, and 99.9% uptime SLA. Our backend is hosted on Render (US), our database on Neon PostgreSQL with connection pooling, and our frontend on Vercel's global edge network behind Cloudflare's DDoS protection and Web Application Firewall.

Cloudflare protection

All traffic to DodoBay products passes through Cloudflare, providing DDoS mitigation, bot protection, SSL termination, and Web Application Firewall (WAF) filtering before reaching our servers.

Database security

Our PostgreSQL database uses connection pooling via PgBouncer, restricts direct internet access, and enforces authentication on all connections. Backups are taken daily and retained for 7 days.

No data sold, ever

DodoBay does not sell, rent, or share your data with advertisers or third parties. Your data is used solely to provide you with the DodoBay service.

Application Security

Hardened by default.

Security headers

DodoBay enforces standard security headers including HTTPS-only access, Content Security Policy, and XSS protection across all products.

Vulnerability management

We conduct regular internal security reviews and maintain a responsible disclosure process for security researchers who identify vulnerabilities in our platform.

Dependency management

Our engineering team regularly audits and updates third-party libraries and dependencies to address known vulnerabilities.

Enterprise buyers

Security documentation on request.

We understand that enterprise procurement teams require documentation before onboarding a new vendor. We're happy to provide the following on request.

Request documentation
  • Completed security questionnaire (CAIQ format)
  • Data Processing Agreement (DPA)
  • Privacy Policy and Terms of Service
  • Infrastructure and architecture overview
  • Data retention and deletion policy

Roadmap

Our security roadmap.

We are committed to continuous improvement of our security posture. Completed and planned milestones include:

Milestone Timeline
Mauritius DPO Registration (Data Controller) Completed
Independent Penetration Test Q4 2026
SOC 2 Type I 2027
SOC 2 Type II 2027–2028
ISO 27001 2028

Get in touch

Questions or concerns?

If you have a security question, want to report a vulnerability, or need documentation for your procurement process, please contact our security team directly.