Skip to content

Security review should not require a second sales call.

Policies, certifications, subprocessors, and review contacts in one place.

Assurance and review artifacts.

Core certifications stay visible. Supporting documents stay one click away.

SOC 2 Type II

Attestation

SOC 2 Type II

Independent Type II attestation of security, availability, and confidentiality controls operating over time, not just at a point in time.
GDPR

Regulation

GDPR

Data handling and customer rights are governed to align with EU privacy requirements, including contractual support during review.
ISO 27001

Certification

ISO 27001

Information security controls are formalized, documented, and maintained in a certified information security management system (ISMS).
ISO 42001

Certification

ISO 42001

AI management system certified to govern responsible development, deployment, and monitoring of artificial intelligence across the platform.

Evidence that holds up in review.

The evidence spans process discovery and live production work. Discovery outputs stay reviewable by the people who run the process; production outcomes stay traceable to what changed, when, and why.

See customer results

Controls reviewers usually ask about.

Encryption, access, monitoring, incident handling, resilience, and audit log export.

  • Incident response alerts

    Monitoring signals are reviewed regularly, and critical alerts are handled through the incident response workflow.

  • Incident response plan

    Duvo follows a documented incident response plan aligned with NIST computer security incident response guidance.

  • Encryption controls

    Encryption at rest and in transit is enforced across the service and its supporting platform architecture.

  • Encryption management

    Encryption keys are managed through managed services rather than ad hoc operator processes.

  • Endpoint encryption

    Company endpoints are required to maintain encryption as part of the baseline security posture.

  • Platform availability monitoring

    Availability monitoring is in place to maintain service continuity against service-level expectations.

  • Platform availability alerts

    Availability alerts are reviewed and addressed according to engineering operating procedures.

  • Platform availability architecture

    The service is deployed on redundant cloud architecture designed to reduce single points of failure.

  • Role-based access

    Access controls include role-based permissions, network protections, and other controls to limit unauthorized access.

  • Access review

    Access to critical systems and delivery resources is reviewed for appropriateness on a recurring schedule.

  • Application authentication

    All user entities authenticate through unique credentials before they can access the service.

  • Single sign-on

    Human access can run through your identity provider with single sign-on.

  • Suspend and revoke

    Write access runs on scoped credentials you control: revoking them, or pausing the automation, stops the agent from acting in your systems.

  • Audit log export

    Run history, approvals, and write-back events can be exported to your security monitoring (SIEM) tools, with retention agreed in the contract.

  • Multi-factor authentication

    Critical systems and resources require MFA as part of the internal access-control baseline.

  • Architecture diagram

    Service architecture and data-flow diagrams are maintained and can be shared with customer reviewers.

  • Vulnerability management

    Platform and external systems are scanned for vulnerabilities, with findings handled through a defined remediation policy.

Use only the access the outcome needs.

Discovery, read-only analysis, and production execution are reviewed separately. Deployment controls are agreed before a workflow runs.

No system access

Start with walkthroughs and documents.

Guided walkthroughs, interviews, and existing documents can establish the process record and improvement case without production access.

Read-only

Add evidence without write permission.

System data, roles, and named datasets can be scoped for analysis without authorizing Duvo to change source records.

Write-capable

Approve production access when it is needed.

Scoped credentials, approval gates, action limits, and replayable logs are added only for an agreed production process. Credentials remain under your control and can be revoked.

Environment controls

Choose where models and data can run.

EU-only or US-only routing, data residency, dedicated AI endpoints, and customer-managed AI endpoints can be agreed during review.

Regional routing, Data residency, Dedicated or customer-managed AI

Model and infrastructure choice

Frontier models, open models, or your own servers.

Duvo is not tied to any AI provider. If a provider changes prices or terms, your process can move to another approved model, agreed with you and reflected in the subprocessor list below. Open models run on EU infrastructure, and deployment on your own hardware is available for data that can never leave.

Cloud, frontier models, Cloud, open models, Your own servers

Operational controls

Set the support and audit path.

Single sign-on, support expectations, escalation paths, and audit exports to your SIEM can be included in the agreement.

SSO and SAML, SIEM and audit export, Support and escalation

Delivery partners

Deloitte
Hatmill
Logio
STROS

Technology providers

Anthropic
ElevenLabs
Microsoft
AWS

Subprocessors are named and scoped.

Every subprocessor that supports the Duvo service is listed with its role below.

  • Google Cloud Platform

    Platform / foundational AI

    Platform and infrastructure hosting services, including compute, storage, and AI capabilities.

  • GitHub

    Development and version control

    Code hosting, versioning, and collaboration workflows used to build and maintain the product.

  • Vercel

    Frontend cloud platform

    Cloud platform used to build, preview, and deploy dynamic web applications.

  • Anthropic

    Foundational AI

    Large language model provider used for AI-driven product capabilities under controlled operating modes.

  • E2B

    Sandboxed execution

    Secure isolated cloud containers used for sandboxed execution and controlled runtime environments.

  • Slack

    Communication and collaboration

    Used as a secure internal and customer-support coordination channel for selected support workflows.

Start with what you can read now.

Public documents are linked here. Others can be requested through MyCroft, our third-party trust portal.

Public

Privacy policy

How Duvo collects, uses, protects, and governs customer information and privacy rights.
Read privacy policy

Public

Terms of Use

The agreement governing use of the Duvo platform, including responsibilities, limitations, and service terms.
Read terms of use

Public

Cookie Policy

How Duvo uses cookies and similar technologies across its websites and services.
Read cookie policy

MyCroft

Review documents in MyCroft

SOC 2 report, ISO 27001 certificate, ISO 42001 certificate, insurance details, and other review artifacts available on request.
Open MyCroft

Direct answers for the first review.

Common questions from security reviews.

  • What happens to our sensitive data?

    Duvo does not train its own or third-party models on customer data. Default model providers run in zero-data-retention mode, so prompts and outputs are not stored. If a customer chooses a provider without that mode, the retention behavior is documented during review.

  • Can we bring our own AI endpoint?

    Yes. Duvo supports customer-managed and dedicated AI endpoints, including single-tenant deployments where teams need tighter control.

  • Can you get EU or US data residency?

    Yes. Hosting, model routing, and browser sandboxes can be constrained to EU-only or US-only infrastructure based on regulatory and internal requirements.

  • How do you ensure confidential data is not exposed within one team?

    Access follows the scope of the user or role that starts the task. Tenant isolation is enforced across the application and data layers, and sensitive actions can require human approval.

  • How is data cached, logged, and versioned during agent execution?

    Duvo minimizes retained data and stores what is needed for auditability and troubleshooting. Logs focus on actions and outcomes, data at rest is encrypted, traffic in transit uses TLS, and run history is tracked with audit trails.

All review documents in one place.

Request security, compliance, or procurement documents directly through MyCroft.