Security is not an FAQ item.
It is core information for the buying decision.
Every item below carries exactly one of five states. We do not write about what we have not yet built as if it were done — we publish the current state of each certification and capability as it is, and we say plainly when something is fixed by contract scope.
Deployment options
Each model shows both what is actually available today and what is fixed by contract scope.
Our safe work permit SaaS runs in production. Organization-level isolation, daily backups.
A cloud environment built exclusively for your organization — delivered according to contract scope.
Designed from the outset to run on customer infrastructure. Open-weight models can be self-served, so the system can operate with no dependency on external APIs — scope and schedule are fixed by contract.
We designed a 100% open-source stack on the premise of deployment into nuclear and public-sector air-gapped networks. Support for the security import review is part of the project contract scope.
Data lifecycle
- No cross-customer learning from customer dataAvailable
A product principle and a contractual term — one customer's calculation sheets and drawings are never used to improve models or rules for another customer.
- Retention and destruction policy for uploaded dataContract scope
Retention periods and destruction procedures are defined per project by contract.
- No-egress configuration for customer dataContract scope
In on-premise and air-gapped deployments, data never leaves the customer boundary.
Model and AI policy
- LLM output is not the official calculation resultAvailable
Arithmetic and determinations are owned by the deterministic engine. The LLM only proposes candidates and explains the evidence behind them.
- Self-hosted open-weight modelsContract scope
Served on our own GPU infrastructure — a deployment can be configured with no external API at all. In cloud deployments, external LLM APIs are used within the contracted scope.
- Abstain by design when confidence is lowAvailable
Weak evidence surfaces as pending review rather than as a pass — we never convert unknown into passed.
Access control and audit
- Role-based access control (RBAC)Contract scope
Each product provides organization- and role-level permissions. Detailed policy follows the adoption scope.
- Review and approval audit logAvailable
Approvals and edits to extracted values are recorded together with the reviewer who made them.
- Append-only audit events and hash-sealed revisionsContract scope
Implemented in the safety permit product line — a submitted revision is sealed with a hash and cannot be altered after the fact.
Method and version integrity
- Version-pinned deterministic kernelAvailable
The same input always produces the same result — the calculation kernel version is recorded with the result.
- No release before the golden-set gate passesAvailable
A review engine is not called released until it has passed the frozen gold-set gate.
- Method Pack with a signed approval recordPlanned
On the doAZ Method product roadmap — the pipeline and verification framework are currently being built.
Human approval boundary
- AI holds no approval authorityAvailable
AI proposes only sourced drafts and candidates. Approval is always performed by an authorized person.
- Maker–checker–approver separation of dutiesContract scope
In the safety permit product line, separation of duties (author is never the approver) is enforced as a rule.
- No approval of safety-related judgments without independent reviewAvailable
A product boundary principle — judgments that bear on safety are never approved without an independent review.
Incident and support process
- Email and phone support channelsAvailable
doaz@doaz.ai · 02-6204-0139 — reply within one business day.
- Contractual SLA (response time and availability)By agreement
Scope and level are agreed within the enterprise contract. There is no standard published SLA yet.
- Scheduled backup and recovery proceduresContract scope
SaaS-operated products run daily backups. Recovery objectives (RTO/RPO) are defined by contract.
Certifications and assessments
- Accredited testing certification (TTA) — measured on a frozen gold setAvailable
Accuracy testing is run with a frozen gold set as the denominator — a structure in which cherry-picking is impossible.
- Information security certification (ISO 27001 · ISMS-P)Planned
Not yet obtained — we do not claim to hold a certification before it is complete.
- Customer security assessment supportContract scope
During evaluation we respond to security questionnaires and due-diligence reviews on a per-project basis.
Do you have a security questionnaire?
We respond to security due diligence and questionnaires on a per-project basis during your evaluation. Air-gapped and on-premise requirements are not a constraint for us — they are the environment we designed for from the start.
Talk to us about a security review