DueFiles
ProductSolutionsPricingResourcesSecurity
Sign inStart free
ProductSolutionsPricingResourcesSecurityContactOpen dashboard

Security and trust

Protect the evidence. Control the decision.

DueFiles separates account access, vendor submissions, document processing, requirement evaluation, and human review so every part of the workflow has a clear security boundary.

Start a security reviewRead the privacy notice

On this page

  1. 01Security model
  2. 02Access boundaries
  3. 03Document intake and validation
  4. 04Extraction and AI boundaries
  5. 05Review accountability
  6. 06Data protection
  7. 07Customer responsibilities
  8. 08Report a vulnerability
  9. 09Enterprise security review

Security reviews and vulnerability reports: security@duefiles.com

Updated September 14, 2026

Security model

DueFiles secures the path from a document request to a final vendor decision. The model separates public website access, account workspaces, scoped vendor submission links, document processing, requirement evaluation, and human review.

This page describes public product behavior. Contractual controls, deployment details, support obligations, and security commitments are established in the applicable Enterprise agreement.

Access boundaries

  • Workspace access: operator routes require an active account session and organization context.
  • Submission access: vendors and brokers use a separate upload-only link, not an operator account.
  • Link lifecycle: submission links carry an expiration and can be rotated by an authorized operator.
  • Organization context: vendor, requirement, document, extraction, and review records carry an organization identifier in the application model.
  • Session handling: application sessions use server-set, HTTP-only cookies with same-site restrictions.

Document intake and validation

The current submission flow accepts text or JSON exports and enforces file type and size limits in the browser and again on the server. A valid, unexpired submission token is required before processing. Submitted content is associated with the intended vendor and organization before extraction begins.

Documents can contain sensitive business information. Users must not send documents through public contact email, issue trackers, or vulnerability reports. Vendor documents belong in the scoped submission workflow provided by the requesting organization.

Extraction and AI boundaries

DueFiles first supports deterministic field and endorsement parsing. When an extraction provider is configured, document text can be sent to that provider to return structured fields and per-field confidence. The extraction instruction requires unknown policy numbers and limits to remain empty instead of being invented.

Extraction is evidence preparation, not verification. Low-confidence fields remain reviewable, and a rejected extraction returns the vendor to a pending state. The organization's authorized users control approvals, rejections, exceptions, and the meaning of each configured requirement.

Review accountability

DueFiles records document ingestion, extraction review, requirement changes, reminders, and vendor decisions as workspace activity. Status logic does not mark an unreviewed or missing packet compliant. A certificate checkbox is not treated as an endorsement, and an extracted value is not treated as a legal coverage determination.

Data protection

Production web traffic is delivered over HTTPS. DueFiles limits service-provider access to the function being performed and uses provider contracts to govern that processing. Retention, deletion, residency, backup, subprocessor, and incident terms vary by deployment and are documented for the applicable Enterprise scope. The Privacy Notice explains data categories, purposes, disclosures, and rights.

Customer responsibilities

Security is shared with each organization using DueFiles. Customers are responsible for:

  • granting access only to authorized users and removing access when responsibilities change;
  • sending submission links only to the intended vendor, broker, or representative;
  • rotating a link that reaches an unintended recipient or is otherwise exposed;
  • reviewing source documents and extraction uncertainty before making a decision;
  • protecting exported data and connected systems; and
  • reporting suspected account misuse, document exposure, or security events promptly.

Report a vulnerability

Send security reports to security@duefiles.com with the affected route or feature, impact, reproducible steps, and a safe proof of concept. Do not include live customer data, credentials, insurance documents, or submission tokens. Use the subject "Security report" so the message is routed correctly.

Research must use accounts and data you control. Do not access another person's information, degrade the service, use social engineering, demand payment, retain data, or disclose an unresolved issue publicly. Stop testing and report immediately if you encounter customer information.

DueFiles will not pursue legal action for good-faith research that follows these rules, avoids harm, and gives DueFiles a reasonable opportunity to investigate and remediate the issue. This safe-harbor commitment does not authorize testing of third-party services or conduct prohibited by law.

Enterprise security review

DueFiles has not published a SOC 2 report, ISO certification, penetration-test report, security rating, or other independent attestation. The absence of a published document is not replaced with a badge or implied claim.

Enterprise evaluations can cover architecture, access, data flow, extraction providers, subprocessors, retention, deletion, incident handling, continuity, connected systems, contract controls, and customer-specific requirements. Contact security@duefiles.com with the organization, deployment scope, data categories, required evidence, and procurement deadline.

DueFiles

The vendor compliance workspace for collecting evidence, applying requirements, resolving gaps, and staying ready for review.

Build your program

Platform

  • Product
  • Pricing
  • Integrations
  • Sign in

Solutions

  • All solutions
  • Property management
  • Community associations
  • Event venues
  • Cleaning companies

Resources

  • Resource center
  • Insurance glossary
  • Comparisons
  • COI field reader
  • Requirement builder

Company

  • About
  • Careers
  • Contact

Trust & legal

  • Security
  • Privacy
  • Terms
  • Accessibility

© 2026 DueFiles. Structured vendor compliance operations.

DueFiles supports document collection and review. It does not issue insurance, amend policies, or replace legal, insurance, or professional judgment.

PrivacyTermsAccessibilitySecurity