Duplios

Security

Honest description of the Duplios preview security posture.

What we implement today

Authenticated application with role-based access control.

Secure session cookies (HttpOnly, Secure, SameSite) and rate-limited login.

Restricted administrative and ingestion operations.

Internal application containers bound to loopback only behind HTTPS reverse proxy.

Audit events for sensitive actions.

OpenAPI documentation hidden in preview.

Current limitations

Shared preview infrastructure with another application on the same host.

SQLite preview database — not production Postgres validation.

No formal security certification is claimed.

Availability is not guaranteed.

Controls continue to evolve.

Responsible disclosure

Report suspected vulnerabilities via the Contact page with enquiry type “Security disclosure”.

Do not attempt destructive testing against production services without prior written permission.

Prototype disclaimer: Duplios is an independent decision-support platform and is not an official government platform. Humans remain responsible for decisions.