Security and trust

Operational intelligence is only useful when the company can trust the system.

Duxor is built on strong company isolation, least privilege, explicit permissions, audit history, location privacy, careful confirmation of AI actions, and clear data ownership.

Security foundations

Part of the operating model from the beginning.

Security and privacy are part of the foundation of Duxor's operating model. These controls protect company, field, customer, and financial data across the V1 service.

Company isolation

Each company's data is logically separated. Every request is scoped by company and user context, with boundaries enforced in the application and data-access layers.

Least privilege

People see only what their role and granted projects require, with detailed control over internal information and the views shared with customers, subcontractors, and vendors.

Audit history

Important changes, approvals, AI-assisted actions, confirmations, imports, integrations, and administrative activity leave a traceable, tamper-resistant record.

Location privacy

Presence and ETA are limited to scheduled work and company policy. Active windows, visible permissions, device state, route and traffic context, geofences, confidence, and manual fallback provide work awareness without all-day tracking.

AI action confirmation

Financial, contractual, external, destructive, and other high-impact actions require review or confirmation; voice and AI do not execute them silently.

Controlled integrations

QuickBooks, SMS, traffic and routing, geofences, jobsite cameras, APIs, and webhooks use scoped credentials, validation, recorded events, and reconciliation where needed.

Technical controls

A practical security architecture.

AreaApproach
IdentityModern authentication, secure session management, single-use email magic links, lockout controls, optional MFA, device controls, and supported SSO for eligible plans.
AuthorizationRole, project, object, audience, and module permissions with least privilege as the default.
EncryptionEncryption in transit and at rest through managed platform services, with secrets stored securely outside application code.
Data isolationCompany boundaries in a multi-tenant architecture, enforced in the application and data-access layers with tenant-aware logging and testing.
AuditImmutable or tamper-resistant history, as appropriate, for permissions, financial actions, approvals, external communication, integration events, and AI-assisted changes.
Files and mediaPrivate object storage, secure time-limited access, metadata validation, retention controls, and malware scanning.
ResilienceBackups, restore testing, monitoring, alerting, incident response, and documented recovery objectives.
PrivacyClear data ownership, retention, deletion, export, and location policies aligned with customer settings, onboarding records, and applicable requirements.

AI accountability

Every action can be explained and reviewed.

Duxor creates structured work without hiding operational facts behind opaque model output.

Each AI-assisted action preserves the source command or conversation, user, time, inputs, resolved people and projects, confidence, clarifying questions, confirmation, and the records or communications created.

When Duxor is uncertain, it says so. When an action has consequences, Duxor shows the proposed result before execution according to company policy. Customer data is not sold or used to train general-purpose outside models.

Have a security, privacy, or architecture question?

We welcome detailed conversations with prospective founding customers and enterprise teams.

Contact Duxor