DUTYSTACK

Trust

Security at DutyStack

DutyStack uses layered application and infrastructure controls. This overview describes verified design and source behavior; it does not claim a certification or contractual service level.

Last updated:

Authentication, roles and revocation

Authenticated web and mobile operations resolve the current user and organisation before protected actions. Canonical roles and permissions restrict administrative and operational capabilities. Owners and authorised administrators can revoke organisation access.

Tenant separation

Customer data is keyed and queried by organisation and, where relevant, workspace. Protected actions and storage services apply organisation-scoped checks. Tenant-isolation tests cover sensitive areas, but no public certification is claimed.

Audit trails

Important organisation, storage, export, sharing and workflow actions create audit or immutable event records. These support investigation and evidence integrity and are not presented as a substitute for customer oversight.

Private documents and controlled sharing

Customer files are catalogued against organisation ownership and stored in private object storage unless a specific managed public asset is intended. Protected files use authorised delivery or short-lived signed access. Evidence shares can be read-only, time-limited and revocable.

Mobile and offline data

The mobile app can store operational data in application storage for offline work and uses platform secure storage for authentication material where supported. Customers should require device passcodes, timely OS updates and rapid access revocation. We do not claim that every offline database field is independently encrypted.

Transport and service boundaries

Production endpoints are intended to be delivered over HTTPS. First-time authentication, authoritative status, uploads, PDF generation, notification delivery and some approvals require online services even when capture is offline-capable.

Reliability, recovery and deletion

Asynchronous workers use durable job records, retries and scheduled recovery for supported workflows. Organisation exports can be prepared before the implemented pending-deletion lifecycle. Backup and disaster-recovery commitments require separate operational verification and are not promised here.

Security and vulnerability reporting

Report suspected unauthorised access, data exposure or a vulnerability through the support contact below. Provide a clear description and safe reproduction details, but do not access data that is not yours, disrupt the service or publicly disclose sensitive details before we can investigate.

Contact DutyStack

Email support@dutystack.co.uk