Dokven

Loading Dokven.

Legal

Security

How Dokven protects your account and Customer Content: encryption in transit, access and ownership controls, target validation, secret handling, sub-processor diligence, and responsible vulnerability disclosure.

Effective: June 16, 2026Last updated: July 16, 2026Version: 1.1.0

1. Our approach

Security is built into how Dokven runs. This page summarizes the measures we use to protect your account and your Customer Content, and how to report a vulnerability. It supports our Privacy Policy and Data Processing Addendum.

2. Technical and organizational measures

  • Encryption in transit: traffic to and from the Service is served over TLS.
  • Access controls: reports, recordings, and artifacts are protected by authentication and ownership checks, so only authorized accounts can access them.
  • Target validation: the Service validates scan targets and blocks requests to private and internal network addresses to reduce the risk of server-side request forgery and misuse.
  • Hardening: the application sets baseline browser security headers, uses a content security policy, and rejects cross-site requests where browser origin signals are available.
  • Secret handling: secrets and login credentials are never stored in saved drafts. The only credential store is an encrypted vault, used at your option for scheduled runs.
  • Sub-processor diligence: we use reputable infrastructure providers and bind them to data-protection terms. See Sub-processors.
  • Retention limits: heavy automation artifacts such as traces and video are auto-purged after about 7 days.

3. Data location

Data is hosted with our infrastructure providers, primarily in the United States, with global edge delivery. See the Privacy Policy for international-transfer safeguards and the Sub-processors list for provider regions.

4. Responsible disclosure

Report a vulnerability

If you discover a security vulnerability in Dokven, please report it privately to support@dokven.combefore disclosing it publicly. Include the affected URL or component, reproduction steps, impact, and any supporting evidence. Do not access or modify other users' data, and do not run tests that degrade the Service.

We will acknowledge credible reports, investigate, and work to remediate promptly. Please act in good faith, avoid privacy violations and service disruption, and give us reasonable time to fix an issue before public disclosure. Do not include secrets in your report attachments.

5. Incident notification

If a personal-data breach affecting your data occurs, we will notify affected users and regulators where and when the law requires, consistent with the Privacy Policy and DPA.

Questions about this document? Contact support@dokven.com (legal) or support@dokven.com (privacy). We review and update these policies as the product and the law change; the version and dates above always reflect the current text.