Trust starts with explicit boundaries.

Public-site controls, project-deployment controls, and independent assurance are different things. This page states what is active now, what is defined with each customer, and what Doku does not yet claim.

Transport and browser controls

Production responses enforce TLS, HSTS, a content security policy, frame denial, and content-type protection.

Request traceability

Qualification requests receive a request ID and no-store responses. Project audit design is scoped separately.

Public-form minimization

The public form requests high-level qualification data and tells applicants not to submit restricted project evidence.

First-party operational telemetry

The public experience uses cookie-free interaction, Core Web Vital, and sanitized runtime events with no advertising trackers.

Abuse controls

Origin checks, request-size limits, timing checks, a honeypot, validation, sanitization, and rate limits protect intake.

Explicit assurance boundary

Doku does not claim SOC 2, ISO 27001, NERC CIP, or independent assurance that has not been earned.

Specific about what exists, and honest about what comes next.

Doku does not claim SOC 2, ISO 27001, NERC CIP certification, or another independent certification unless explicitly stated in current signed security materials. Production scope is subject to a customer security review, architecture definition, data inventory, and signed agreement.

  • Shadow modeControlled files, exports, or read-only integrations.
  • Identity and accessLeast privilege, organization boundaries, and customer-controlled identity where supported.
  • Data protectionEncryption in transit and at rest in production environments.
  • AI review boundaryAI may extract and propose. Accountable experts retain approval authority.

Control-status matrix

AreaPublic siteProject deploymentStatus
Identity and accessNo customer accountsDefined per customer architectureProject prerequisite
Data collectionHigh-level qualification onlyApproved data inventory and scopeActive now
Transport and browser policyTLS, HSTS, CSP, frame denial, and no sniffingExtended for the selected architectureActive now
Application intakeValidation, abuse controls, rate limiting, and request IDsWorkflow-specific monitoring and retentionActive now
AI model useNone in public formDefined in signed security materialsProject prerequisite
Audit and evidenceApplication and operational loggingProject-specific audit designPartially implemented
Independent assuranceNot claimedScoped to customer requirements and maturityNot claimed

Security is not a feature. It is our foundation.