Company isolation
Each company's data is logically separated. Every request is scoped by company and user context, with boundaries enforced in the application and data-access layers.
Security and trust
Duxor is built on strong company isolation, least privilege, explicit permissions, audit history, location privacy, careful confirmation of AI actions, and clear data ownership.
Security foundations
Security and privacy are part of the foundation of Duxor's operating model. These controls protect company, field, customer, and financial data across the V1 service.
Each company's data is logically separated. Every request is scoped by company and user context, with boundaries enforced in the application and data-access layers.
People see only what their role and granted projects require, with detailed control over internal information and the views shared with customers, subcontractors, and vendors.
Important changes, approvals, AI-assisted actions, confirmations, imports, integrations, and administrative activity leave a traceable, tamper-resistant record.
Presence and ETA are limited to scheduled work and company policy. Active windows, visible permissions, device state, route and traffic context, geofences, confidence, and manual fallback provide work awareness without all-day tracking.
Financial, contractual, external, destructive, and other high-impact actions require review or confirmation; voice and AI do not execute them silently.
QuickBooks, SMS, traffic and routing, geofences, jobsite cameras, APIs, and webhooks use scoped credentials, validation, recorded events, and reconciliation where needed.
Technical controls
| Area | Approach |
|---|---|
| Identity | Modern authentication, secure session management, single-use email magic links, lockout controls, optional MFA, device controls, and supported SSO for eligible plans. |
| Authorization | Role, project, object, audience, and module permissions with least privilege as the default. |
| Encryption | Encryption in transit and at rest through managed platform services, with secrets stored securely outside application code. |
| Data isolation | Company boundaries in a multi-tenant architecture, enforced in the application and data-access layers with tenant-aware logging and testing. |
| Audit | Immutable or tamper-resistant history, as appropriate, for permissions, financial actions, approvals, external communication, integration events, and AI-assisted changes. |
| Files and media | Private object storage, secure time-limited access, metadata validation, retention controls, and malware scanning. |
| Resilience | Backups, restore testing, monitoring, alerting, incident response, and documented recovery objectives. |
| Privacy | Clear data ownership, retention, deletion, export, and location policies aligned with customer settings, onboarding records, and applicable requirements. |
AI accountability
Duxor creates structured work without hiding operational facts behind opaque model output.
Each AI-assisted action preserves the source command or conversation, user, time, inputs, resolved people and projects, confidence, clarifying questions, confirmation, and the records or communications created.
When Duxor is uncertain, it says so. When an action has consequences, Duxor shows the proposed result before execution according to company policy. Customer data is not sold or used to train general-purpose outside models.
We welcome detailed conversations with prospective founding customers and enterprise teams.