D
Damira AI

Security & Data Privacy

How Damira AI handles your data — PII redaction, execution modes, data retention, and enterprise deployment.

Your network configurations, command outputs, and device data are sensitive. Damira AI is built with data protection as a core design principle, not an afterthought.

PII Redaction

Before any data is processed by the AI model, Damira automatically strips sensitive information from your input:

Data TypeWhat Happens
Public IP addressesReplaced with safe placeholders (10.99.x.x range)
Passwords & secretsPermanently redacted — cannot be recovered
SNMP community stringsReplaced with generic labels
Customer namesReplaced with anonymous identifiers
Hostnames & FQDNsReplaced with generic device labels
Banner textStripped of identifying information

This happens automatically on every request. You don't need to sanitize configs before pasting them. When the AI responds, Damira restores the original values in your output so the commands are ready to use.

After redaction, a verification step confirms that no sensitive values survived in the processed text. If any leak is detected, it's logged for review.

Execution Modes

Damira operates in three security modes that control how it interacts with your network:

Advisor Mode (Default)

The assistant recommends commands but never executes anything on your devices. You run the commands yourself and paste the output back. Your device data stays entirely within your network.

This is always the default. You don't need to configure anything — Damira starts in advisor mode automatically.

Guided Mode (Opt-in)

Each command is shown to you for explicit approval before execution. Nothing runs without your "Approve" action. Use this when you trust the connection but want human-in-the-loop control.

Lab Mode (Explicit)

Commands execute automatically on connected devices. Only available for designated test environments. Must be explicitly enabled — never activates by default.

Data Retention

WhatRetention
Chat messagesStay in your Cursor or Claude Code session — not stored on Damira servers
Network configs you pasteProcessed in-memory, not stored after the session
Generated documentsSaved to your local machine in the output folder you configure
Research briefsDeep research results are saved on Damira servers, scoped to your account, so later questions can reuse them
Monitoring dataAlerts, metrics and log excerpts you paste are redacted like any other input and not stored

Monitoring Data

Damira doesn't connect to your monitoring stack. You paste alerts, metric snapshots, or log excerpts into your AI session, and they get the same PII redaction as any other input. Damira never holds monitoring credentials and can't change dashboards, alerts, or tickets. See Monitoring & Alerts.

Local Stats & Telemetry

Every automation-generator validate run appends one line to a log file on your own machine (~/.damira/logs/workflows.jsonl). Run damira stats to see your own first-pass rate, retries-to-green, and top failing checks from that file — nothing is sent anywhere by default.

What's collected, if you opt in: check names, pass/fail/warn counts, file extensions, skill and vendor labels, plugin version, an attempt number, and time to green — never file content, file names or paths, hostnames, IPs, credentials, or tool output. Values that look like any of those are dropped before the line is even written locally.

Opt in: set DAMIRA_TELEMETRY=1 to have events re-scrubbed and uploaded in batches to Damira's own analytics, tied to your API key. The shared demo key never uploads, and upload is best effort — it never blocks validation. Set DAMIRA_WORKFLOW_LOG=0 to turn off local logging entirely. Eval runs upload their own tagged events regardless of this setting, since they're testing Damira itself rather than your network.

Enterprise Deployment

Organizations requiring full control can self-host Damira:

  • Your infrastructure — AI processing runs on your GPUs (AWS, Azure, or on-prem)
  • Zero data retention — Damira provides the agent software; you own the data and models
  • No external calls — All processing stays within your network boundary
  • SOC 2 compliant — The AI processing infrastructure meets SOC 2 requirements

Rate Limiting

Every plan has a daily query limit and a per-minute limit; Enterprise has no daily limit. If you exceed a limit, you'll receive a clear error with a Retry-After header indicating when you can resume.

PlanDaily query limitPer-minute
Free505
Starter30015
Pro80020
Team2,00060
EnterpriseNo daily limit100

On this page