Buyer security brief

Security & data handling

DurationX uses a minimum-identification intake: enough technical context to evaluate an assumption, without requiring an exact project address, coordinates, or named vendor. It is not a zero-data service—the assumptions you submit are processed to produce and review the decision brief.

Project label

Alias accepted

Evidence files

Optional and redactable

Delivered PDF

Signed and verifiable

01 · Data minimization

What you do—and do not—need to disclose

Project identity
Use an internal alias such as “Project X”. A legal or public project name is not required for the audit.
Location
Country and a regional site descriptor select the applicable benchmark cohort. Exact coordinates are not required.
Commercial parties
Vendor identities and contract terms are not required unless you choose to use them as evidence for a project-specific exception.
Documents
Supporting documents are optional. You may redact proprietary or personal information that is not needed for the review.

Your business identity and payment record are not anonymous. The country remains required because geographic benchmark coverage is part of the methodology.

02 · Processing

How a decision brief is produced

  1. 1

    Intake

    You submit structured technical assumptions and, optionally, redacted evidence.

  2. 2

    Evaluation

    Version-pinned scoring and benchmark comparisons produce the readiness evidence.

  3. 3

    Draft & review

    AI assists with narrative drafting; compliance checks and human quality control precede delivery.

  4. 4

    Delivery

    The signed PDF is stored privately and delivered through authenticated links.

03 · Controls

Security controls in the production design

Access
Customer and administrator access is authenticated. Administrative access is role-gated from server-verified account metadata.
Storage
Reports, intake evidence, benchmark source artifacts, and methodology records are kept in private storage buckets rather than public file paths.
Database
Row-level access policies and service-role boundaries restrict access to project and report records.
Transport
The public service uses HTTPS. Report downloads use authenticated or time-limited access paths.
Report integrity
Delivered PDFs are Ed25519-signed. The public verification page can confirm that a report is authentic and unaltered.
Operations
Security and audit events are logged; production separates the web application, database, and analysis-worker credentials.

No online service can promise absolute security. DurationX does not claim SOC 2 or ISO 27001 certification.

04 · Providers

Named systems that support the service

ProviderPurpose
SupabaseDatabase, authentication, private storage, and backups
VercelWebsite and API hosting
HetznerAnalysis worker infrastructure
AnthropicAI-assisted narrative drafting and compliance review
ResendTransactional email
PaddleMerchant-of-record payment processing

Provider roles, international-transfer safeguards, and retention detail are maintained in the Privacy Policy.

05 · Retention & requests

Retention is defined; deletion is requestable

Qualification records, paid-audit inputs, evidence, report metadata, delivery events, and security logs have defined retention windows. Verified deletion requests are processed subject to legal, tax, fraud-prevention, dispute, and security holds. The complete retention matrix and request procedure are published in the Privacy Policy.

Security contact

Need a buyer-security answer before qualification?

Contact support@durationx.com. We can answer questions about data flow, providers, retention, and the minimum information needed for an audit.