Back to security and trust

Reviewed July 23, 2026

Start the security review with a shared control boundary.

This public summary helps a prospective design partner identify what is active on the website, what must be defined before project evidence is exchanged, and what Doku Infrastructure does not yet claim. It is not a certification, audit report, contract, or substitute for customer-specific security materials.

Public intake
High-level qualification only
Restricted evidence
Not accepted before approved scope
Public accounts
None
Public-form AI use
None
Independent assurance
Not claimed
Security contact
jorg@dokuinfra.com

Controls a reviewer can evaluate now

  • TLS delivery with HSTS, content security policy, frame denial, content-type protection, strict referrer policy, and restricted browser permissions.
  • High-level qualification intake only, with explicit instructions not to submit restricted project evidence.
  • Origin, content-type, request-size, timing, honeypot, validation, sanitization, and process-local rate-limit checks on application intake.
  • Opaque request IDs and no-store responses for intake and delivery-status endpoints.
  • No customer accounts, shared-model training, or AI processing in the public application form.
  • Cookie-free first-party interaction, Core Web Vital, and sanitized runtime-failure events with no advertising trackers.

Decisions required before evidence exchange

  1. 01

    Identify the contracting party, accountable customer owner, approved users, and participating organizations.

  2. 02

    Approve the data inventory, classification, source authority, permitted use, and prohibited information before transfer.

  3. 03

    Document deployment architecture, identity, least privilege, organization boundaries, encryption, logging, and approved integrations.

  4. 04

    Agree retention, export, deletion, discovery, legal-hold, residency, backup, and recovery requirements.

  5. 05

    Define any AI model provider, processing location, training restriction, human-review boundary, and model-use record.

  6. 06

    Document incident contacts, notification expectations, support path, change control, and exit procedure in signed materials.

No trust claim by implication.

Doku Infrastructure does not claim SOC 2, ISO 27001, NERC CIP certification, an independent penetration test, or another independent assurance unless it is explicitly stated in current signed materials.

The website controls described here do not establish the controls of a future customer deployment. Project controls become commitments only when documented in an approved architecture and signed agreement.

Software supports accountable review. It does not replace it.

ActivityDoku BasisCustomer and responsible experts
Source evidenceLinks facts to sources, owners, versions, and review states.Choose authoritative sources and approve access.
Change impactExtracts, proposes, traces, and presents affected objects.Review technical consequences and approve disposition.
Project decisionRecords ownership, deadlines, rationale, and closure evidence.Retain professional, contractual, and executive authority.
Security scopeImplements the agreed technical boundary.Approve architecture, data use, users, and policy requirements.

Seven questions to resolve before detailed diligence.

  1. 01
    Scope

    Which single workflow, project gate, data sources, and participating organizations are in scope?

  2. 02
    Authority

    Which source systems and accountable experts remain authoritative for each governed fact?

  3. 03
    Data

    What information may enter the deployment, and what information must remain outside it?

  4. 04
    Access

    Who may view, propose, approve, export, or administer project information?

  5. 05
    AI use

    Where may AI assist, which provider is approved, and where is human approval mandatory?

  6. 06
    Evidence

    Which logs, approvals, exports, and closure records must be retained, and for how long?

  7. 07
    Operations

    Who owns incidents, access changes, support, recovery, termination, and verified deletion?

Bring the project boundary, not restricted evidence.

Start with the selected workflow, participating organizations, target architecture, data classes, and review requirements.

Request customer-specific review materials