Skip to main content

Trust starts with the boundary, not the badge.

Review implemented controls, explicit limitations, declared subprocessors, and the evidence paths behind Doctorine's security posture.

The posture we can explain today.

Each statement names the control and the limit around it. Architecture intent alone is never treated as customer evidence.

  • 01

    Database-backed tenant isolation

    Tenant-scoped tables use Postgres FORCE ROW LEVEL SECURITY, and the committed test harness exercises cross-tenant probes as a non-owner application role. Application authorization remains an additional layer rather than the only boundary.

  • 02

    EU data-at-rest for the core data plane

    Core content and tenant stores are configured in EU regions. 11 of 16 declared rows are EU-resident; 5 non-EU carve-outs cover services such as authentication, payments, and consented acquisition analytics. This is not a claim of EU-only edge processing.

  • 03

    Content security and framing controls are surface-specific

    This marketing site ships a build-time hash policy without unsafe-inline script, while frame-ancestors none is delivered in its HTTP response header. Dashboard and portal policies are tested separately; we do not claim that every first-party surface has an identical style policy.

  • 04

    Immutable release artifacts with explicit activation

    The publishing path writes content-addressed release artifacts and activates a selected release through a pointer. That makes rollback deterministic, but it does not turn the design into a guarantee that every edge, storage, or operational outage is impossible.

  • 05

    Crypto-shred erasure with proof gates

    The implemented erasure flow destroys the scoped data-encryption key, reconciles every declared store, and emits a completion receipt only after clean verification. Production assurance still depends on configured adapters and an end-to-end operational receipt.

  • 06

    Auditable staff-access paths

    Supported staff impersonation sessions and back-office actions are written to audited tables and projected into the customer activity feed. We do not treat an audit row as a substitute for access policy, review, or incident response.

Residency with the carve-outs visible.

EU data-at-rest by construction; US carve-outs are disclosed rows, never hidden (docs 04/19/34).

The full subprocessor table is generated from the CI-gated residency manifest. Dependencies matching declared vendor markers cannot pass the trust-surface gate without a disclosed row; contract and infrastructure review cover data flows package markers cannot detect.

Review subprocessors and residency

Compliance without borrowed certainty.

Doctorine does not currently claim SOC 2 certification. We act as processor for customer workspace content under applicable terms, with transfer bases disclosed for non-EU subprocessors. An automated breach clock and delivery receipt remain rollout work.

Bring the security questions into the pilot.

Start with a public or synthetic release while your team reviews access, data flow, and procurement boundaries.

Become a Design Partner