- Organisation data is tenant-scoped. Cross-tenant reads fail closed.
- Server-side role checks decide who can read, write, review, invite, export or manage billing.
- Private documents are stored separately from public passport drafts.
- Authentication tokens and API secrets are hashed, not stored in recoverable form.
- Billing webhooks require a signed payload, a known test account, and an allowlisted price.
- AI suggestions, when enabled later, remain review items. They do not become accepted product data by themselves.
How DPPLogic isolates customer work.
These are implemented product controls. This page does not claim ISO 27001, SOC 2, or any other certification.