Updated September 14, 2026
Security model
DueFiles secures the path from a document request to a final vendor decision. The model separates public website access, account workspaces, scoped vendor submission links, document processing, requirement evaluation, and human review.
This page describes public product behavior. Contractual controls, deployment details, support obligations, and security commitments are established in the applicable Enterprise agreement.
Access boundaries
- Workspace access: operator routes require an active account session and organization context.
- Submission access: vendors and brokers use a separate upload-only link, not an operator account.
- Link lifecycle: submission links carry an expiration and can be rotated by an authorized operator.
- Organization context: vendor, requirement, document, extraction, and review records carry an organization identifier in the application model.
- Session handling: application sessions use server-set, HTTP-only cookies with same-site restrictions.
Document intake and validation
The current submission flow accepts text or JSON exports and enforces file type and size limits in the browser and again on the server. A valid, unexpired submission token is required before processing. Submitted content is associated with the intended vendor and organization before extraction begins.
Documents can contain sensitive business information. Users must not send documents through public contact email, issue trackers, or vulnerability reports. Vendor documents belong in the scoped submission workflow provided by the requesting organization.
Extraction and AI boundaries
DueFiles first supports deterministic field and endorsement parsing. When an extraction provider is configured, document text can be sent to that provider to return structured fields and per-field confidence. The extraction instruction requires unknown policy numbers and limits to remain empty instead of being invented.
Extraction is evidence preparation, not verification. Low-confidence fields remain reviewable, and a rejected extraction returns the vendor to a pending state. The organization's authorized users control approvals, rejections, exceptions, and the meaning of each configured requirement.
Review accountability
DueFiles records document ingestion, extraction review, requirement changes, reminders, and vendor decisions as workspace activity. Status logic does not mark an unreviewed or missing packet compliant. A certificate checkbox is not treated as an endorsement, and an extracted value is not treated as a legal coverage determination.
Data protection
Production web traffic is delivered over HTTPS. DueFiles limits service-provider access to the function being performed and uses provider contracts to govern that processing. Retention, deletion, residency, backup, subprocessor, and incident terms vary by deployment and are documented for the applicable Enterprise scope. The Privacy Notice explains data categories, purposes, disclosures, and rights.
Customer responsibilities
Security is shared with each organization using DueFiles. Customers are responsible for:
- granting access only to authorized users and removing access when responsibilities change;
- sending submission links only to the intended vendor, broker, or representative;
- rotating a link that reaches an unintended recipient or is otherwise exposed;
- reviewing source documents and extraction uncertainty before making a decision;
- protecting exported data and connected systems; and
- reporting suspected account misuse, document exposure, or security events promptly.
Report a vulnerability
Send security reports to security@duefiles.com with the affected route or feature, impact, reproducible steps, and a safe proof of concept. Do not include live customer data, credentials, insurance documents, or submission tokens. Use the subject "Security report" so the message is routed correctly.
Research must use accounts and data you control. Do not access another person's information, degrade the service, use social engineering, demand payment, retain data, or disclose an unresolved issue publicly. Stop testing and report immediately if you encounter customer information.
DueFiles will not pursue legal action for good-faith research that follows these rules, avoids harm, and gives DueFiles a reasonable opportunity to investigate and remediate the issue. This safe-harbor commitment does not authorize testing of third-party services or conduct prohibited by law.
Enterprise security review
DueFiles has not published a SOC 2 report, ISO certification, penetration-test report, security rating, or other independent attestation. The absence of a published document is not replaced with a badge or implied claim.
Enterprise evaluations can cover architecture, access, data flow, extraction providers, subprocessors, retention, deletion, incident handling, continuity, connected systems, contract controls, and customer-specific requirements. Contact security@duefiles.com with the organization, deployment scope, data categories, required evidence, and procurement deadline.