Duplios
Security
Honest description of the Duplios preview security posture.
What we implement today
Authenticated application with role-based access control.
Secure session cookies (HttpOnly, Secure, SameSite) and rate-limited login.
Restricted administrative and ingestion operations.
Internal application containers bound to loopback only behind HTTPS reverse proxy.
Audit events for sensitive actions.
OpenAPI documentation hidden in preview.
Current limitations
Shared preview infrastructure with another application on the same host.
SQLite preview database — not production Postgres validation.
No formal security certification is claimed.
Availability is not guaranteed.
Controls continue to evolve.
Responsible disclosure
Report suspected vulnerabilities via the Contact page with enquiry type “Security disclosure”.
Do not attempt destructive testing against production services without prior written permission.
Prototype disclaimer: Duplios is an independent decision-support platform and is not an official government platform. Humans remain responsible for decisions.