Skip to content
Trust · Deployment Center

Security is not an FAQ item.
It is core information for the buying decision.

Every item below carries exactly one of five states. We do not write about what we have not yet built as if it were done — we publish the current state of each certification and capability as it is, and we say plainly when something is fixed by contract scope.

AvailableAvailable — verifiable today in the shipping product and in live operation
Contract scopeAvailable within contract scope — technically available; scope and level are fixed by contract
PlannedPlanned — on the roadmap but not yet delivered; never shown as complete
Not supportedNot supported — not offered today
By agreementBy agreement — customer-specific approval must come first

Deployment options

Each model shows both what is actually available today and what is fixed by contract scope.

Multi-tenant SaaSAvailable

Our safe work permit SaaS runs in production. Organization-level isolation, daily backups.

Dedicated VPCContract scope

A cloud environment built exclusively for your organization — delivered according to contract scope.

On-premiseContract scope

Designed from the outset to run on customer infrastructure. Open-weight models can be self-served, so the system can operate with no dependency on external APIs — scope and schedule are fixed by contract.

Air-gappedContract scope

We designed a 100% open-source stack on the premise of deployment into nuclear and public-sector air-gapped networks. Support for the security import review is part of the project contract scope.

Data lifecycle

  • No cross-customer learning from customer data

    A product principle and a contractual term — one customer's calculation sheets and drawings are never used to improve models or rules for another customer.

    Available
  • Retention and destruction policy for uploaded data

    Retention periods and destruction procedures are defined per project by contract.

    Contract scope
  • No-egress configuration for customer data

    In on-premise and air-gapped deployments, data never leaves the customer boundary.

    Contract scope

Model and AI policy

  • LLM output is not the official calculation result

    Arithmetic and determinations are owned by the deterministic engine. The LLM only proposes candidates and explains the evidence behind them.

    Available
  • Self-hosted open-weight models

    Served on our own GPU infrastructure — a deployment can be configured with no external API at all. In cloud deployments, external LLM APIs are used within the contracted scope.

    Contract scope
  • Abstain by design when confidence is low

    Weak evidence surfaces as pending review rather than as a pass — we never convert unknown into passed.

    Available

Access control and audit

  • Role-based access control (RBAC)

    Each product provides organization- and role-level permissions. Detailed policy follows the adoption scope.

    Contract scope
  • Review and approval audit log

    Approvals and edits to extracted values are recorded together with the reviewer who made them.

    Available
  • Append-only audit events and hash-sealed revisions

    Implemented in the safety permit product line — a submitted revision is sealed with a hash and cannot be altered after the fact.

    Contract scope

Method and version integrity

  • Version-pinned deterministic kernel

    The same input always produces the same result — the calculation kernel version is recorded with the result.

    Available
  • No release before the golden-set gate passes

    A review engine is not called released until it has passed the frozen gold-set gate.

    Available
  • Method Pack with a signed approval record

    On the doAZ Method product roadmap — the pipeline and verification framework are currently being built.

    Planned

Human approval boundary

  • AI holds no approval authority

    AI proposes only sourced drafts and candidates. Approval is always performed by an authorized person.

    Available
  • Maker–checker–approver separation of duties

    In the safety permit product line, separation of duties (author is never the approver) is enforced as a rule.

    Contract scope
  • No approval of safety-related judgments without independent review

    A product boundary principle — judgments that bear on safety are never approved without an independent review.

    Available

Incident and support process

  • Email and phone support channels

    doaz@doaz.ai · 02-6204-0139 — reply within one business day.

    Available
  • Contractual SLA (response time and availability)

    Scope and level are agreed within the enterprise contract. There is no standard published SLA yet.

    By agreement
  • Scheduled backup and recovery procedures

    SaaS-operated products run daily backups. Recovery objectives (RTO/RPO) are defined by contract.

    Contract scope

Certifications and assessments

  • Accredited testing certification (TTA) — measured on a frozen gold set

    Accuracy testing is run with a frozen gold set as the denominator — a structure in which cherry-picking is impossible.

    Available
  • Information security certification (ISO 27001 · ISMS-P)

    Not yet obtained — we do not claim to hold a certification before it is complete.

    Planned
  • Customer security assessment support

    During evaluation we respond to security questionnaires and due-diligence reviews on a per-project basis.

    Contract scope

Do you have a security questionnaire?

We respond to security due diligence and questionnaires on a per-project basis during your evaluation. Air-gapped and on-premise requirements are not a constraint for us — they are the environment we designed for from the start.

Talk to us about a security review