Security at dpow.app

Last updated 6 October 2026

dpow.app is run by DPOW Group Ltd (company number 17276695). This page says plainly how we protect your data, and what we have not done yet. To report a vulnerability, see Reporting a vulnerability below.

Certifications

DPOW Group Ltd does not hold ISO 27001, SOC 2, Cyber Essentials or any other security certification at present. No independent penetration test has been carried out yet. Our hosting and AI providers hold their own certifications; ask us and we will point you to them.

Where your data lives

WhatWhereProvider
Your project filesIn your own Microsoft 365 SharePoint, under your organisation's control (exceptions below)Microsoft, under your own Microsoft agreement
The register, programme, RFIs, audit trail, chat history and settingsdpow's databaseSupabase Inc.
The app itself and its server codeHosting and content deliveryVercel Inc.
Service emailsEmail delivery, United StatesResend (Plus Five Five, Inc.)
PaymentsCard payments and invoices. Card details are handled by Stripe only and never reach dpowStripe
AI processingSee AI belowOpenAI and Anthropic, or your own provider

The full list of companies we use, and what each one does, is our sub-processor list. Some of them are in the United States; transfers are covered as set out in our data processing agreement.

Files that are held by dpow, not in your SharePoint

Your files stay in your SharePoint, with these exceptions:

  1. Files SharePoint refuses. If SharePoint will not accept an upload, dpow keeps a private copy until someone moves it into SharePoint, for up to 90 days.
  2. RFI, variation and submittal attachments, and site photos uploaded in the app are held in dpow's private storage.
  3. Organisation logos and profile photos are held in a storage area that can be read by anyone who has the exact link.
  4. 3D models uploaded to the scope viewer are held in dpow's private storage.
  5. Fee proposals are written to dpow's private storage if SharePoint is not available.
  6. Text for AI. When you use an AI feature, the text it needs is sent to the AI provider (see AI). The AI reading of a tender pack, chat answers, and a searchable text index of register rows are kept in dpow's database.

Private storage is reached only through short lived signed links, issued after a check that the person belongs to your organisation.

How access is controlled

Microsoft 365: delegated access only

dpow works in your Microsoft 365 as the person who is signed in. It uses delegated permissions only: it never holds an application permission across your tenant, and it can never do more than the signed in person's own Microsoft account is allowed to do. Your Microsoft administrator stays in control and can remove dpow at any time in the Microsoft Entra admin centre. The permissions we ask for, and why, are listed in dpow.app for your IT team.

The audit trail

Every significant action is recorded in an audit trail that no one can edit or delete, including dpow's own server: a database rule blocks every change. The person and time on each entry are set by the system, not typed in. The audit trail is kept for 6 years after the project closes. Entries are only ever removed whole, by two locked database functions: the 6 year retention purge, and deleting an organisation that has left (see the retention periods).

AI

Logs and personal data

Emails, tokens and keys are masked before anything is written to a log. The error log keeps the route, a redacted message and the app version only, for 90 days.

What we have not done yet

We would rather tell you than have you find out:

  1. No malware scan of uploads. Files are checked for type, size and content signature, but are not scanned for viruses.
  2. No independent penetration test has been carried out yet.
  3. No security certification is held (see above).
  4. The content security policy still allows some inline scripts.
  5. Logos and profile photos are readable by anyone with the exact link (see above).

Reporting a vulnerability

Email pc at dpow.co.uk. The same address is published in our security.txt file at dpow.app/.well-known/security.txt and at datum.dpow.app/.well-known/security.txt.

Please include the address of the page, what you did, what you saw and how to reproduce it. Do not access, change or keep other people's data beyond what is needed to show the problem, and do not run denial of service or automated scanning against the live service. We will acknowledge within 2 working days and tell you what we are doing about it. We will not take action against good faith research that follows these rules.

If something goes wrong

We keep a written personal data breach plan. If a breach affects your organisation's data we will tell your account admin without undue delay, as our data processing agreement sets out, so you can meet your own duties.

Questions

Email pc at dpow.co.uk. Our data processing agreement is at dpow.app/dpa.html.