Buyer security brief
Security & data handling
DurationX uses a minimum-identification intake: enough technical context to evaluate an assumption, without requiring an exact project address, coordinates, or named vendor. It is not a zero-data service—the assumptions you submit are processed to produce and review the decision brief.
Project label
Alias accepted
Evidence files
Optional and redactable
Delivered PDF
Signed and verifiable
01 · Data minimization
What you do—and do not—need to disclose
- Project identity
- Use an internal alias such as “Project X”. A legal or public project name is not required for the audit.
- Location
- Country and a regional site descriptor select the applicable benchmark cohort. Exact coordinates are not required.
- Commercial parties
- Vendor identities and contract terms are not required unless you choose to use them as evidence for a project-specific exception.
- Documents
- Supporting documents are optional. You may redact proprietary or personal information that is not needed for the review.
Your business identity and payment record are not anonymous. The country remains required because geographic benchmark coverage is part of the methodology.
02 · Processing
How a decision brief is produced
1
Intake
You submit structured technical assumptions and, optionally, redacted evidence.
2
Evaluation
Version-pinned scoring and benchmark comparisons produce the readiness evidence.
3
Draft & review
AI assists with narrative drafting; compliance checks and human quality control precede delivery.
4
Delivery
The signed PDF is stored privately and delivered through authenticated links.
03 · Controls
Security controls in the production design
- Access
- Customer and administrator access is authenticated. Administrative access is role-gated from server-verified account metadata.
- Storage
- Reports, intake evidence, benchmark source artifacts, and methodology records are kept in private storage buckets rather than public file paths.
- Database
- Row-level access policies and service-role boundaries restrict access to project and report records.
- Transport
- The public service uses HTTPS. Report downloads use authenticated or time-limited access paths.
- Report integrity
- Delivered PDFs are Ed25519-signed. The public verification page can confirm that a report is authentic and unaltered.
- Operations
- Security and audit events are logged; production separates the web application, database, and analysis-worker credentials.
No online service can promise absolute security. DurationX does not claim SOC 2 or ISO 27001 certification.
04 · Providers
Named systems that support the service
| Provider | Purpose |
|---|---|
| Supabase | Database, authentication, private storage, and backups |
| Vercel | Website and API hosting |
| Hetzner | Analysis worker infrastructure |
| Anthropic | AI-assisted narrative drafting and compliance review |
| Resend | Transactional email |
| Paddle | Merchant-of-record payment processing |
Provider roles, international-transfer safeguards, and retention detail are maintained in the Privacy Policy.
05 · Retention & requests
Retention is defined; deletion is requestable
Qualification records, paid-audit inputs, evidence, report metadata, delivery events, and security logs have defined retention windows. Verified deletion requests are processed subject to legal, tax, fraud-prevention, dispute, and security holds. The complete retention matrix and request procedure are published in the Privacy Policy.
Security contact
Need a buyer-security answer before qualification?
Contact support@durationx.com. We can answer questions about data flow, providers, retention, and the minimum information needed for an audit.