Kept apart by company.
Each company’s data lives in its own encrypted volume with its own key. Our tools refuse any command that would reach another company’s data.
Security
Our engineers work inside your company’s systems, so security is built into how the work is done. Each company’s data is kept apart, access is enforced in code, every action is recorded and deletion is certified.
Six rules hold for every company we work with, and our software enforces them.
Each company’s data lives in its own encrypted volume with its own key. Our tools refuse any command that would reach another company’s data.
Our connectors to your finance systems are built to read only, over HTTPS connections that verify the server they reach. Nothing in them writes to your records.
What we build prepares the work, such as collection emails. Your team reviews it and decides what goes out. Our software cannot send email.
A tamper-evident log records who did what, when and for which company, with signed checkpoints. It records actions, never your data values.
Passwords and keys for your systems stay in the operating system’s secure keychain, never in files, logs or error messages.
When we leave, we erase your data by destroying its keys, as NIST SP 800-88 describes, and give you a signed deletion certificate confirmed by a second person.
How your data is handled from the first agreement to the day we leave.
A written agreement sets what we may access and why, with a data processing agreement where the law requires one. We name the people who can reach your data and set up encrypted storage for your company alone.
Only the named people can open your company’s data, and our connectors only read from your systems. Every action is logged, and anything that changes your records or reaches your customers goes through your team first.
We revoke our access to your systems, erase your data and hand you a signed certificate. It lists anything we could not reach, such as copies already in your own email.
Where models are used, and who stays in control.
Some companies we work with have their own obligations. We sign the terms those rules require before any regulated data reaches us.
What we test today, and what comes next.
If you think you’ve found a vulnerability, tell us.
Email info@doranlabs.com with “Security” in the subject line. Describe the issue and the steps to reproduce it. We aim to reply within three business days and will keep you updated until it is fixed.
Please give us reasonable time to fix an issue before you share it, and do not access, change or delete data that isn’t yours, degrade our services or test against our clients’ systems. We will not pursue legal action against research carried out in good faith within these limits. Our contact details are also published in security.txt.
Send your security questionnaire or ask for a walkthrough of how an engagement is protected, from the first agreement to deletion.