Security at dpow.app
dpow.app is run by DPOW Group Ltd (company number 17276695). This page says plainly how we protect your data, and what we have not done yet. To report a vulnerability, see Reporting a vulnerability below.
Certifications
DPOW Group Ltd does not hold ISO 27001, SOC 2, Cyber Essentials or any other security certification at present. No independent penetration test has been carried out yet. Our hosting and AI providers hold their own certifications; ask us and we will point you to them.
Where your data lives
| What | Where | Provider |
|---|---|---|
| Your project files | In your own Microsoft 365 SharePoint, under your organisation's control (exceptions below) | Microsoft, under your own Microsoft agreement |
| The register, programme, RFIs, audit trail, chat history and settings | dpow's database | Supabase Inc. |
| The app itself and its server code | Hosting and content delivery | Vercel Inc. |
| Service emails | Email delivery, United States | Resend (Plus Five Five, Inc.) |
| Payments | Card payments and invoices. Card details are handled by Stripe only and never reach dpow | Stripe |
| AI processing | See AI below | OpenAI and Anthropic, or your own provider |
The full list of companies we use, and what each one does, is our sub-processor list. Some of them are in the United States; transfers are covered as set out in our data processing agreement.
Files that are held by dpow, not in your SharePoint
Your files stay in your SharePoint, with these exceptions:
- Files SharePoint refuses. If SharePoint will not accept an upload, dpow keeps a private copy until someone moves it into SharePoint, for up to 90 days.
- RFI, variation and submittal attachments, and site photos uploaded in the app are held in dpow's private storage.
- Organisation logos and profile photos are held in a storage area that can be read by anyone who has the exact link.
- 3D models uploaded to the scope viewer are held in dpow's private storage.
- Fee proposals are written to dpow's private storage if SharePoint is not available.
- Text for AI. When you use an AI feature, the text it needs is sent to the AI provider (see AI). The AI reading of a tender pack, chat answers, and a searchable text index of register rows are kept in dpow's database.
Private storage is reached only through short lived signed links, issued after a check that the person belongs to your organisation.
How access is controlled
- Encryption in transit. All connections to dpow.app use HTTPS, with HSTS so browsers refuse plain connections.
- Organisation isolation. Every database table has row level security, so a signed in user can only read rows belonging to an organisation they are a member of. An automated test reads every table, signed out and as a member of another organisation, and must find nothing. Separate automated tests try to reach another organisation's data through the app's API.
- Every API request checked. Every request is checked for a valid sign in and, for anything belonging to an organisation, project or file, for membership of that organisation. Writing actions also check the person's role, so Viewers cannot change anything. All 109 API routes were reviewed on 5 October 2026 and the issues found were fixed.
- Client portals. Each client portal is protected by an access code. Codes are stored only as a hash tied to that portal, and issuing a new code ends the old one.
- Uploads. File type checks, size limits, content sniffing of the first bytes, safe file names, and only images and PDFs are ever shown inline.
- Rate limits are in place on public forms and AI use.
- Security headers. Content security policy, frame protection, nosniff, referrer and permissions policies.
- Webhooks. Payment and messaging webhooks are signature checked and fail closed.
Microsoft 365: delegated access only
dpow works in your Microsoft 365 as the person who is signed in. It uses delegated permissions only: it never holds an application permission across your tenant, and it can never do more than the signed in person's own Microsoft account is allowed to do. Your Microsoft administrator stays in control and can remove dpow at any time in the Microsoft Entra admin centre. The permissions we ask for, and why, are listed in dpow.app for your IT team.
- Tokens encrypted at rest. Microsoft connection tokens are encrypted with AES-256-GCM and cannot be read from the browser.
- Disconnect. Settings, Integrations, Disconnect Microsoft clears the tokens. They are also cleared if Microsoft refuses a refresh.
The audit trail
Every significant action is recorded in an audit trail that no one can edit or delete, including dpow's own server: a database rule blocks every change. The person and time on each entry are set by the system, not typed in. The audit trail is kept for 6 years after the project closes. Entries are only ever removed whole, by two locked database functions: the 6 year retention purge, and deleting an organisation that has left (see the retention periods).
AI
- AI reads only what a user asks it to: the files they select, the text they paste, or the register data needed to answer their question.
- By default AI requests go to OpenAI and Anthropic on dpow's own accounts. Both providers' API terms state that they do not train their models on API customer data by default.
- Both providers keep API data for a limited time for abuse monitoring (Anthropic: deleted within 30 days by default; OpenAI: up to 30 days), longer only where flagged for policy breaches.
- Your own AI key. An organisation admin can add its own key (Anthropic, OpenAI, Azure OpenAI or Gemini, or another OpenAI compatible provider). AI requests then run on your own account under your own contract. Keys are encrypted at rest (AES-256-GCM), are only used on the server, and are never shown back in full.
- AI cannot take actions: it can only return text, which the app checks before use.
- AI generated documents are drafts for your review before issue.
Logs and personal data
Emails, tokens and keys are masked before anything is written to a log. The error log keeps the route, a redacted message and the app version only, for 90 days.
What we have not done yet
We would rather tell you than have you find out:
- No malware scan of uploads. Files are checked for type, size and content signature, but are not scanned for viruses.
- No independent penetration test has been carried out yet.
- No security certification is held (see above).
- The content security policy still allows some inline scripts.
- Logos and profile photos are readable by anyone with the exact link (see above).
Reporting a vulnerability
Email pc at dpow.co.uk. The same address is published in our security.txt file at dpow.app/.well-known/security.txt and at datum.dpow.app/.well-known/security.txt.
Please include the address of the page, what you did, what you saw and how to reproduce it. Do not access, change or keep other people's data beyond what is needed to show the problem, and do not run denial of service or automated scanning against the live service. We will acknowledge within 2 working days and tell you what we are doing about it. We will not take action against good faith research that follows these rules.
If something goes wrong
We keep a written personal data breach plan. If a breach affects your organisation's data we will tell your account admin without undue delay, as our data processing agreement sets out, so you can meet your own duties.
Questions
Email pc at dpow.co.uk. Our data processing agreement is at dpow.app/dpa.html.