Security

Security by structure,
not by promise.

Our engineers work inside your company’s systems, so security is built into how the work is done. Each company’s data is kept apart, access is enforced in code, every action is recorded and deletion is certified.

Principles

Six rules hold for every company we work with, and our software enforces them.

Kept apart by company.

Each company’s data lives in its own encrypted volume with its own key. Our tools refuse any command that would reach another company’s data.

Read-only by default.

Our connectors to your finance systems are built to read only, over HTTPS connections that verify the server they reach. Nothing in them writes to your records.

Software drafts, people send.

What we build prepares the work, such as collection emails. Your team reviews it and decides what goes out. Our software cannot send email.

Every action on the record.

A tamper-evident log records who did what, when and for which company, with signed checkpoints. It records actions, never your data values.

Credentials never in the clear.

Passwords and keys for your systems stay in the operating system’s secure keychain, never in files, logs or error messages.

Deletion you can verify.

When we leave, we erase your data by destroying its keys, as NIST SP 800-88 describes, and give you a signed deletion certificate confirmed by a second person.

Engagement lifecycle

How your data is handled from the first agreement to the day we leave.

  1. Before we start

    A written agreement sets what we may access and why, with a data processing agreement where the law requires one. We name the people who can reach your data and set up encrypted storage for your company alone.

  2. While we work

    Only the named people can open your company’s data, and our connectors only read from your systems. Every action is logged, and anything that changes your records or reaches your customers goes through your team first.

  3. When we leave

    We revoke our access to your systems, erase your data and hand you a signed certificate. It lists anything we could not reach, such as copies already in your own email.

AI and agents

Where models are used, and who stays in control.

Your data trains only your models.
We never use one company’s data to train a model for another company.
Frontier models, private channels.
We run frontier models through secure enterprise services such as Amazon Bedrock, where model providers never receive your data and it is never used for training. We turn on zero data retention wherever a model allows it, and your agreement names each model and how it handles data.
People approve what matters.
Agents work within the permissions your agreement sets. Anything that changes your records or reaches your customers waits for a person on your team.
Fund reporting without raw records.
Portfolio analytics use company-level figures. Individual records stay with each company, and customer names never reach fund reports.

Regulated industries

Some companies we work with have their own obligations. We sign the terms those rules require before any regulated data reaches us.

Healthcare.
We sign a business associate agreement before handling protected health information, hold our own service providers to the same terms, and limit our access to the minimum the work needs.
Financial services.
We sign the service-provider terms that the FTC Safeguards Rule, SEC Regulation S-P and New York’s cybersecurity rules ask of your vendors, answer your due diligence, and notify you within 72 hours of a breach affecting your customers’ information.
Card payments.
We do not take in payment card numbers. Our work uses the reports your systems already produce, which keeps us out of your card environment.
Personal data in the EU and UK.
We act only on your written instructions under a data processing agreement with standard contractual clauses, and tell you which service providers we use before they touch your data. For EU fund managers and insurers, we add the contract terms the Digital Operational Resilience Act requires.

Assurance

What we test today, and what comes next.

Tested on every release.
Automated tests check that credentials never reach logs or error messages, that no command crosses between companies and that our software cannot send email. A release that fails them does not ship.
Independent audits.
We don’t yet hold a SOC 2 report or an ISO 27001 certificate, and we’ll say so plainly until we do. SOC 2 is on our roadmap. Until then we answer your security questionnaire and walk your team through our controls.
Questions and documents.
Email info@doranlabs.com for our security overview or to send your due diligence questionnaire.

Report an issue

If you think you’ve found a vulnerability, tell us.

Email info@doranlabs.com with “Security” in the subject line. Describe the issue and the steps to reproduce it. We aim to reply within three business days and will keep you updated until it is fixed.

Please give us reasonable time to fix an issue before you share it, and do not access, change or delete data that isn’t yours, degrade our services or test against our clients’ systems. We will not pursue legal action against research carried out in good faith within these limits. Our contact details are also published in security.txt.

Ask us how
we protect it.

Send your security questionnaire or ask for a walkthrough of how an engagement is protected, from the first agreement to deletion.