Transport and browser controls
Production responses enforce TLS, HSTS, a content security policy, frame denial, and content-type protection.
Security & trust
Public-site controls, project-deployment controls, and independent assurance are different things. This page states what is active now, what is defined with each customer, and what Doku does not yet claim.
Production responses enforce TLS, HSTS, a content security policy, frame denial, and content-type protection.
Qualification requests receive a request ID and no-store responses. Project audit design is scoped separately.
The public form requests high-level qualification data and tells applicants not to submit restricted project evidence.
The public experience uses cookie-free interaction, Core Web Vital, and sanitized runtime events with no advertising trackers.
Origin checks, request-size limits, timing checks, a honeypot, validation, sanitization, and rate limits protect intake.
Doku does not claim SOC 2, ISO 27001, NERC CIP, or independent assurance that has not been earned.
Current control boundary
Doku does not claim SOC 2, ISO 27001, NERC CIP certification, or another independent certification unless explicitly stated in current signed security materials. Production scope is subject to a customer security review, architecture definition, data inventory, and signed agreement.
| Area | Public site | Project deployment | Status |
|---|---|---|---|
| Identity and access | No customer accounts | Defined per customer architecture | Project prerequisite |
| Data collection | High-level qualification only | Approved data inventory and scope | Active now |
| Transport and browser policy | TLS, HSTS, CSP, frame denial, and no sniffing | Extended for the selected architecture | Active now |
| Application intake | Validation, abuse controls, rate limiting, and request IDs | Workflow-specific monitoring and retention | Active now |
| AI model use | None in public form | Defined in signed security materials | Project prerequisite |
| Audit and evidence | Application and operational logging | Project-specific audit design | Partially implemented |
| Independent assurance | Not claimed | Scoped to customer requirements and maturity | Not claimed |
Security is not a feature. It is our foundation.