NillaNinja ← Back to Business Dojo

NILLANINJA BUSINESS DOJO

Security & Privacy

Business Dojo is being built to remember how a business operates. Protecting that memory is therefore part of the product itself, not an optional feature added later.

OUR APPROACH

We intend to earn the right to hold business context by designing for security, privacy, transparency, and user control from the beginning.

01

Security by design

Security is a core product requirement for Business Dojo.

As the product moves from public demonstration into private beta and production use, the infrastructure handling customer accounts, business information, and persistent memory will be designed around appropriate access controls, secure authentication, encrypted connections, protected data storage, monitoring, backups, and responsible operational practices.

Business Dojo will not treat security as something to bolt onto the product after businesses have already trusted us with meaningful data.

02

Your business data belongs to you

Business Dojo is designed to help a business understand and improve its own operations. The information a business provides remains that business's information.

We do not believe using Business Dojo should require a business to surrender ownership of its operating knowledge, Snapshot history, processes, outcomes, or other business context.

Your business memory should work for your business—not become somebody else's asset.

03

Dojo Mind is private business memory

Dojo Mind is intended to preserve the context that makes Business Dojo more useful over time.

That may include previous Snapshots, recommendations, actions, outcomes, lessons, recurring work, adopted practices, and business systems created through continued use.

The purpose of that memory is to help Business Dojo understand the history and operating context of the business using it. It is not intended to turn one business's knowledge into another business's product experience.

04

AI should have boundaries

AI may assist Business Dojo with interpretation, explanation, organization, contextual guidance, and future assisted workflows. That does not mean every piece of stored business information should automatically be sent to an AI model.

Production architecture will be designed to control when AI is used, what context is necessary for a particular task, and how much information needs to be shared to accomplish it.

As specific AI services and infrastructure are finalized, Business Dojo will document how those services interact with customer data rather than hiding that relationship behind vague language.

05

Collect what is useful. Avoid what is not.

Business Dojo follows a data-minimization principle: collect and retain information because it serves a clear product purpose, not simply because it can be collected.

Business improvement requires context, but more data is not automatically better data. The product should ask for information that helps the business understand, improve, measure, remember, or systemize its operations.

06

Access should be controlled

Production Business Dojo accounts will require appropriate authentication and authorization controls so that business information is available only to people and systems that should have access to it.

The exact account, team, permission, and administrative controls will evolve with the product, but preventing inappropriate access is a foundational requirement of the production system.

07

Encryption is a production requirement

Production infrastructure will be expected to protect data while it moves between users and Business Dojo and while persistent customer information is stored.

Specific implementation details will depend on the final hosting, database, authentication, backup, and application architecture. Those controls will be documented as the production platform is finalized.

08

Export and deletion matter

Business memory should not become a trap.

As persistent customer accounts are introduced, Business Dojo is intended to provide meaningful ways for users to retrieve their information and request removal of stored business data when they no longer want the service to retain it.

Exact export formats, retention periods, backup handling, and deletion procedures will be defined before broader production use.

09

No pretend compliance

Business Dojo will not display security certifications, compliance badges, audit claims, or standards language that the product has not actually earned or implemented.

Frameworks and certifications such as SOC 2 may become appropriate as the company, customer base, and product mature. If Business Dojo reaches those milestones, we will say so when the evidence exists.

Trust should come from real controls and transparent practices, not security theater.

10

The public demo is not the production data platform

The current Business Dojo Lite demonstration exists to show the product experience and methodology while production infrastructure is still being prepared.

Persistent customer accounts, centralized business memory, production authentication, backend storage, and the full security architecture belong to the production platform that will support private beta and later releases.

We would rather clearly distinguish those stages than imply the public demonstration already represents the final production environment.

11

Security will evolve with the product

No responsible security program is ever permanently finished.

As Business Dojo grows, security practices will need to grow with the sensitivity of the information being stored, the number of businesses using the platform, the features being introduced, and the threats the system needs to withstand.

That means reviewing infrastructure, dependencies, access, monitoring, incident response, backups, data handling, AI integrations, and applicable compliance requirements as the product develops.

THE COMMITMENT

A useful business memory has to be a trusted business memory.

Business Dojo is being built around long-term context. If a business is going to trust the system with the story of how it operates, what it tried, what worked, what failed, and what it learned, protecting that information has to be part of the foundation.

We will continue publishing clearer technical and policy details as the production architecture, beta infrastructure, and data practices are finalized.