Unreadable by default.
Protected resources are encrypted and designed so routine support, administration, and infrastructure operations cannot reveal their contents.
Security & Trust
DUIID is designed for information that can affect a person’s safety, money, work, family, and future. Security therefore shapes ownership, permissions, recovery, operations, and every product decision—not only encryption.
This public overview describes protection goals and user guarantees. Sensitive infrastructure details and provider inventories are intentionally not published.Protection commitments
Protected resources are encrypted and designed so routine support, administration, and infrastructure operations cannot reveal their contents.
Sharing identifies who may do what, with which resource, for what purpose, and for how long. Owners can review and revoke access.
Recovery uses multiple paths, notifications, delay where risk warrants it, and safeguards against turning help into account takeover.
Personal, family, professional, and organization contexts retain distinct ownership, administration, billing, and privacy boundaries.
Important changes, access decisions, recovery events, exports, transfers, and administrative actions are recorded for review and investigation.
The system is designed for device loss, compromise, service disruption, incapacity, succession, ownership transfer, and orderly shutdown.
Non-negotiables
DUIID minimizes personal data, metadata, copies, and retention so there is less to expose or misuse.
Creating a resource does not make it public. Publication, sharing, and delegation require an intentional audience decision.
Signing in, administering a workspace, recovering an account, and reading protected content are different authorities.
People, staff, devices, services, and automations receive the least authority needed, for the shortest practical time.
Export, revocation, recovery, transfer, archival, and closure are first-class controls—not retention obstacles.
Security claims are backed by tests, operational evidence, scoped assessment, and clearly dated assurance statements.
Threat-informed design
DUIID plans for compromised accounts and devices, malicious insiders, unsafe support, deceptive invitations, coerced sharing, recovery abuse, hostile recipients, public-profile misuse, integration risk, service disruption, and disputes between people with competing claims.
No system can recall information a legitimate recipient already copied, guarantee recovery after every recovery path is destroyed, or remove all risk from human decisions. DUIID explains meaningful residual risk at the moment a person shares, delegates, recovers, transfers, or closes.
Public material explains commitments and safe use. Detailed infrastructure, defensive configuration, and attack-response procedures remain restricted to authorized reviewers and operators.
Assurance program
Threat modeling, privacy review, peer review, automated checks, misuse testing, dependency controls, and release gates follow consequential changes.
Staff access is least-privileged, time-limited where practical, approved for sensitive actions, monitored, and recorded for investigation.
Security monitoring prioritizes account takeover, permission abuse, unusual recovery, data exposure, service misuse, and control failure.
Incidents follow defined ownership, severity, containment, evidence preservation, customer communication, recovery, and learning processes.
Independent assessment and structured testing challenge both product controls and the operational paths around them.
Published certifications and assessment summaries identify what was reviewed, when it was reviewed, and what the conclusion does—and does not—cover.
Enterprise buyers, auditors, and qualified security reviewers may request deeper assurance material through a controlled review process. Public disclosure remains detailed enough to establish commitments without becoming an infrastructure map.
Send reproduction steps, the affected page or component, likely impact, and a safe contact method. Do not access other people’s data, use social engineering, or disrupt the service while testing.