Security review should not require a second sales call.
Policies, certifications, subprocessors, and review contacts in one place.
Assurance and review artifacts.
Core certifications stay visible. Supporting documents stay one click away.
Attestation
SOC 2 Type II
Regulation
GDPR
Certification
ISO 27001
Certification
ISO 42001
Evidence that holds up in review.
The evidence spans process discovery and live production work. Discovery outputs stay reviewable by the people who run the process; production outcomes stay traceable to what changed, when, and why.
See customer resultsControls reviewers usually ask about.
Encryption, access, monitoring, incident handling, resilience, and audit log export.
Incident response alerts
Monitoring signals are reviewed regularly, and critical alerts are handled through the incident response workflow.
Incident response plan
Duvo follows a documented incident response plan aligned with NIST computer security incident response guidance.
Encryption controls
Encryption at rest and in transit is enforced across the service and its supporting platform architecture.
Encryption management
Encryption keys are managed through managed services rather than ad hoc operator processes.
Endpoint encryption
Company endpoints are required to maintain encryption as part of the baseline security posture.
Platform availability monitoring
Availability monitoring is in place to maintain service continuity against service-level expectations.
Platform availability alerts
Availability alerts are reviewed and addressed according to engineering operating procedures.
Platform availability architecture
The service is deployed on redundant cloud architecture designed to reduce single points of failure.
Role-based access
Access controls include role-based permissions, network protections, and other controls to limit unauthorized access.
Access review
Access to critical systems and delivery resources is reviewed for appropriateness on a recurring schedule.
Application authentication
All user entities authenticate through unique credentials before they can access the service.
Single sign-on
Human access can run through your identity provider with single sign-on.
Suspend and revoke
Write access runs on scoped credentials you control: revoking them, or pausing the automation, stops the agent from acting in your systems.
Audit log export
Run history, approvals, and write-back events can be exported to your security monitoring (SIEM) tools, with retention agreed in the contract.
Multi-factor authentication
Critical systems and resources require MFA as part of the internal access-control baseline.
Architecture diagram
Service architecture and data-flow diagrams are maintained and can be shared with customer reviewers.
Vulnerability management
Platform and external systems are scanned for vulnerabilities, with findings handled through a defined remediation policy.
Use only the access the outcome needs.
Discovery, read-only analysis, and production execution are reviewed separately. Deployment controls are agreed before a workflow runs.
No system access
Start with walkthroughs and documents.
Guided walkthroughs, interviews, and existing documents can establish the process record and improvement case without production access.
Read-only
Add evidence without write permission.
System data, roles, and named datasets can be scoped for analysis without authorizing Duvo to change source records.
Write-capable
Approve production access when it is needed.
Scoped credentials, approval gates, action limits, and replayable logs are added only for an agreed production process. Credentials remain under your control and can be revoked.
Environment controls
Choose where models and data can run.
EU-only or US-only routing, data residency, dedicated AI endpoints, and customer-managed AI endpoints can be agreed during review.
Regional routing, Data residency, Dedicated or customer-managed AI
Model and infrastructure choice
Frontier models, open models, or your own servers.
Duvo is not tied to any AI provider. If a provider changes prices or terms, your process can move to another approved model, agreed with you and reflected in the subprocessor list below. Open models run on EU infrastructure, and deployment on your own hardware is available for data that can never leave.
Cloud, frontier models, Cloud, open models, Your own servers
Operational controls
Set the support and audit path.
Single sign-on, support expectations, escalation paths, and audit exports to your SIEM can be included in the agreement.
SSO and SAML, SIEM and audit export, Support and escalation
Delivery partners
Technology providers
Subprocessors are named and scoped.
Every subprocessor that supports the Duvo service is listed with its role below.

Google Cloud Platform
Platform / foundational AI
Platform and infrastructure hosting services, including compute, storage, and AI capabilities.

GitHub
Development and version control
Code hosting, versioning, and collaboration workflows used to build and maintain the product.

Vercel
Frontend cloud platform
Cloud platform used to build, preview, and deploy dynamic web applications.

Anthropic
Foundational AI
Large language model provider used for AI-driven product capabilities under controlled operating modes.

E2B
Sandboxed execution
Secure isolated cloud containers used for sandboxed execution and controlled runtime environments.
Slack
Communication and collaboration
Used as a secure internal and customer-support coordination channel for selected support workflows.
Start with what you can read now.
Public documents are linked here. Others can be requested through MyCroft, our third-party trust portal.
Public
Privacy policy
Public
Terms of Use
Public
Cookie Policy
MyCroft
Review documents in MyCroft
Direct answers for the first review.
Common questions from security reviews.
What happens to our sensitive data?
Duvo does not train its own or third-party models on customer data. Default model providers run in zero-data-retention mode, so prompts and outputs are not stored. If a customer chooses a provider without that mode, the retention behavior is documented during review.
Can we bring our own AI endpoint?
Yes. Duvo supports customer-managed and dedicated AI endpoints, including single-tenant deployments where teams need tighter control.
Can you get EU or US data residency?
Yes. Hosting, model routing, and browser sandboxes can be constrained to EU-only or US-only infrastructure based on regulatory and internal requirements.
How do you ensure confidential data is not exposed within one team?
Access follows the scope of the user or role that starts the task. Tenant isolation is enforced across the application and data layers, and sensitive actions can require human approval.
How is data cached, logged, and versioned during agent execution?
Duvo minimizes retained data and stores what is needed for auditability and troubleshooting. Logs focus on actions and outcomes, data at rest is encrypted, traffic in transit uses TLS, and run history is tracked with audit trails.
All review documents in one place.
Request security, compliance, or procurement documents directly through MyCroft.