Operational trust
Pilot security
Duevia is designed so an AI proposal never silently becomes an action. This page describes implemented controls and current limitations without claiming certifications we do not hold.
Principles
- AI proposes; a person confirms.
- Every finding retains its page, quote and calculation.
- All public demo data is synthetic.
- Real documents are accepted only inside the authenticated pilot.
- Least privilege is the default.
Pilot controls
- HTTPS transport and strict security headers.
- Secure sessions, invite-only access and repeated-attempt protection.
- Files outside public paths, random internal names and type/size validation.
- Workspace isolation in every query and operation.
- Action logs that exclude document content from operational logging.
- Deletion of originals, extracted text, obligations and derived reminders.
Document processing
The local pilot extracts text and candidates using components controlled by Duevia. A verifier requires a locatable source before presenting a finding. Document content is untrusted: it cannot instruct the system to send mail, delete data or take actions.
Current limits
Duevia does not claim ISO, SOC 2 or sector-specific certification. It does not guarantee that an extraction is complete or legally correct. Regulated data, health records, employee credentials or particularly sensitive information require a separate assessment and agreement.
Report a vulnerability
Email admin@duevia.site with a reproducible description. Do not include real documents or secrets in the first message. We will acknowledge receipt and coordinate an appropriate channel.