Public due-diligence summary
Reviewed July 23, 2026
Start the security review with a shared control boundary.
This public summary helps a prospective design partner identify what is active on the website, what must be defined before project evidence is exchanged, and what Doku Infrastructure does not yet claim. It is not a certification, audit report, contract, or substitute for customer-specific security materials.
- Public intake
- High-level qualification only
- Restricted evidence
- Not accepted before approved scope
- Public accounts
- None
- Public-form AI use
- None
- Independent assurance
- Not claimed
- Security contact
- jorg@dokuinfra.com
Verified public-site boundary
Controls a reviewer can evaluate now
- TLS delivery with HSTS, content security policy, frame denial, content-type protection, strict referrer policy, and restricted browser permissions.
- High-level qualification intake only, with explicit instructions not to submit restricted project evidence.
- Origin, content-type, request-size, timing, honeypot, validation, sanitization, and process-local rate-limit checks on application intake.
- Opaque request IDs and no-store responses for intake and delivery-status endpoints.
- No customer accounts, shared-model training, or AI processing in the public application form.
- Cookie-free first-party interaction, Core Web Vital, and sanitized runtime-failure events with no advertising trackers.
Project deployment boundary
Decisions required before evidence exchange
- 01
Identify the contracting party, accountable customer owner, approved users, and participating organizations.
- 02
Approve the data inventory, classification, source authority, permitted use, and prohibited information before transfer.
- 03
Document deployment architecture, identity, least privilege, organization boundaries, encryption, logging, and approved integrations.
- 04
Agree retention, export, deletion, discovery, legal-hold, residency, backup, and recovery requirements.
- 05
Define any AI model provider, processing location, training restriction, human-review boundary, and model-use record.
- 06
Document incident contacts, notification expectations, support path, change control, and exit procedure in signed materials.
Assurance boundary
No trust claim by implication.
Doku Infrastructure does not claim SOC 2, ISO 27001, NERC CIP certification, an independent penetration test, or another independent assurance unless it is explicitly stated in current signed materials.
The website controls described here do not establish the controls of a future customer deployment. Project controls become commitments only when documented in an approved architecture and signed agreement.
Responsibility boundary
Software supports accountable review. It does not replace it.
| Activity | Doku Basis | Customer and responsible experts |
|---|---|---|
| Source evidence | Links facts to sources, owners, versions, and review states. | Choose authoritative sources and approve access. |
| Change impact | Extracts, proposes, traces, and presents affected objects. | Review technical consequences and approve disposition. |
| Project decision | Records ownership, deadlines, rationale, and closure evidence. | Retain professional, contractual, and executive authority. |
| Security scope | Implements the agreed technical boundary. | Approve architecture, data use, users, and policy requirements. |
First review meeting
Seven questions to resolve before detailed diligence.
- 01Scope
Which single workflow, project gate, data sources, and participating organizations are in scope?
- 02Authority
Which source systems and accountable experts remain authoritative for each governed fact?
- 03Data
What information may enter the deployment, and what information must remain outside it?
- 04Access
Who may view, propose, approve, export, or administer project information?
- 05AI use
Where may AI assist, which provider is approved, and where is human approval mandatory?
- 06Evidence
Which logs, approvals, exports, and closure records must be retained, and for how long?
- 07Operations
Who owns incidents, access changes, support, recovery, termination, and verified deletion?
Customer-specific review
Bring the project boundary, not restricted evidence.
Start with the selected workflow, participating organizations, target architecture, data classes, and review requirements.