Security
How Dokven protects your account and Customer Content: encryption in transit, access and ownership controls, target validation, secret handling, sub-processor diligence, and responsible vulnerability disclosure.
On this page
1. Our approach
Security is built into how Dokven runs. This page summarizes the measures we use to protect your account and your Customer Content, and how to report a vulnerability. It supports our Privacy Policy and Data Processing Addendum.
2. Technical and organizational measures
- Encryption in transit: traffic to and from the Service is served over TLS.
- Access controls: reports, recordings, and artifacts are protected by authentication and ownership checks, so only authorized accounts can access them.
- Target validation: the Service validates scan targets and blocks requests to private and internal network addresses to reduce the risk of server-side request forgery and misuse.
- Hardening: the application sets baseline browser security headers, uses a content security policy, and rejects cross-site requests where browser origin signals are available.
- Secret handling: secrets and login credentials are never stored in saved drafts. The only credential store is an encrypted vault, used at your option for scheduled runs.
- Sub-processor diligence: we use reputable infrastructure providers and bind them to data-protection terms. See Sub-processors.
- Retention limits: heavy automation artifacts such as traces and video are auto-purged after about 7 days.
3. Data location
Data is hosted with our infrastructure providers, primarily in the United States, with global edge delivery. See the Privacy Policy for international-transfer safeguards and the Sub-processors list for provider regions.
4. Responsible disclosure
Report a vulnerability
We will acknowledge credible reports, investigate, and work to remediate promptly. Please act in good faith, avoid privacy violations and service disruption, and give us reasonable time to fix an issue before public disclosure. Do not include secrets in your report attachments.
5. Incident notification
If a personal-data breach affecting your data occurs, we will notify affected users and regulators where and when the law requires, consistent with the Privacy Policy and DPA.
Questions about this document? Contact support@dokven.com (legal) or support@dokven.com (privacy). We review and update these policies as the product and the law change; the version and dates above always reflect the current text.