Trust
Security
We're a small team in public beta, so this page states what's actually true today, not a roadmap. For the full picture, see our Privacy Policy.
What we store
Scan content is processed to generate your verdict and stored only as an audit log entry (score, verdict, and the checks that ran) tied to your tenant. Delete any scan or your whole account at any time - see Privacy Policy.
Encryption
All traffic to dokeo.co and the scoring API runs over TLS 1.2+. Account and scan data at rest lives on an AES-256 encrypted volume.
Access
API requests are authenticated with per-tenant HMAC-protected keys. Session cookies are HttpOnly, Secure, and SameSite=Lax. All user-supplied URLs (batch scans, webhook deliveries) are SSRF-guarded before we fetch them.
Payments
Payments are handled by Stripe and Razorpay. We never see or store your card or UPI details.
Data residency
We run single-region today (US). Multi-region with EU/MENA data residency is planned but not live - we won't claim regional residency until it's actually shipped and holding your data.
Subprocessors
- Fly.io - application hosting and data storage
- Vercel - marketing site and app front end
- Stripe / Razorpay - payment processing
- Zhipu AI (z.ai) - AI-powered rewrites only, on scans you opt into
Compliance
We haven't completed a SOC 2 audit yet - we're a small team and haven't claimed one we don't have. If you need a security questionnaire for procurement or a beta reference, email os@dokeo.co.
Reporting a vulnerability
Found an issue? Email os@dokeo.co with details and we'll respond within one business day.