Skip to content

Security & Trust

Your identity should not require blind trust.

DUIID is designed for information that can affect a person’s safety, money, work, family, and future. Security therefore shapes ownership, permissions, recovery, operations, and every product decision—not only encryption.

This public overview describes protection goals and user guarantees. Sensitive infrastructure details and provider inventories are intentionally not published.

Protection commitments

Control that holds under pressure.

Private content

Unreadable by default.

Protected resources are encrypted and designed so routine support, administration, and infrastructure operations cannot reveal their contents.

Explicit access

Every grant has a boundary.

Sharing identifies who may do what, with which resource, for what purpose, and for how long. Owners can review and revoke access.

Safe recovery

Availability without a back door.

Recovery uses multiple paths, notifications, delay where risk warrants it, and safeguards against turning help into account takeover.

Realm separation

Work authority stops at work.

Personal, family, professional, and organization contexts retain distinct ownership, administration, billing, and privacy boundaries.

Accountable action

Sensitive events leave evidence.

Important changes, access decisions, recovery events, exports, transfers, and administrative actions are recorded for review and investigation.

Continuity

Security survives a bad day.

The system is designed for device loss, compromise, service disruption, incapacity, succession, ownership transfer, and orderly shutdown.

Non-negotiables

Rules every feature must preserve.

  1. 01

    Collect less

    DUIID minimizes personal data, metadata, copies, and retention so there is less to expose or misuse.

  2. 02

    Default to private

    Creating a resource does not make it public. Publication, sharing, and delegation require an intentional audience decision.

  3. 03

    Separate powers

    Signing in, administering a workspace, recovering an account, and reading protected content are different authorities.

  4. 04

    Limit every actor

    People, staff, devices, services, and automations receive the least authority needed, for the shortest practical time.

  5. 05

    Keep the owner in control

    Export, revocation, recovery, transfer, archival, and closure are first-class controls—not retention obstacles.

  6. 06

    Require evidence

    Security claims are backed by tests, operational evidence, scoped assessment, and clearly dated assurance statements.

Threat-informed design

Designed for mistakes and adversaries.

Legitimate-looking access can still be abuse.DUIID security principle

DUIID plans for compromised accounts and devices, malicious insiders, unsafe support, deceptive invitations, coerced sharing, recovery abuse, hostile recipients, public-profile misuse, integration risk, service disruption, and disputes between people with competing claims.

No system can recall information a legitimate recipient already copied, guarantee recovery after every recovery path is destroyed, or remove all risk from human decisions. DUIID explains meaningful residual risk at the moment a person shares, delegates, recovers, transfers, or closes.

Responsible detail

Public material explains commitments and safe use. Detailed infrastructure, defensive configuration, and attack-response procedures remain restricted to authorized reviewers and operators.

Assurance program

Trust is maintained, not announced.

Build

Secure from design to release.

Threat modeling, privacy review, peer review, automated checks, misuse testing, dependency controls, and release gates follow consequential changes.

Operate

Restrict exceptional power.

Staff access is least-privileged, time-limited where practical, approved for sensitive actions, monitored, and recorded for investigation.

Detect

Watch for meaningful signals.

Security monitoring prioritizes account takeover, permission abuse, unusual recovery, data exposure, service misuse, and control failure.

Respond

Contain, recover, communicate.

Incidents follow defined ownership, severity, containment, evidence preservation, customer communication, recovery, and learning processes.

Verify

Test the promise.

Independent assessment and structured testing challenge both product controls and the operational paths around them.

Disclose

Scope every assurance claim.

Published certifications and assessment summaries identify what was reviewed, when it was reviewed, and what the conclusion does—and does not—cover.

Security questions deserve useful answers.

Enterprise buyers, auditors, and qualified security reviewers may request deeper assurance material through a controlled review process. Public disclosure remains detailed enough to establish commitments without becoming an infrastructure map.

security@duiid.com

Found something that could hurt someone?

Send reproduction steps, the affected page or component, likely impact, and a safe contact method. Do not access other people’s data, use social engineering, or disrupt the service while testing.

Report securely