Menu

Trust centre

Security designed around product and tenant boundaries

DPP Grid uses tenant-scoped authorization, encrypted secrets and personal data, private evidence storage, security headers, audit events and tested backup/rollback procedures.

Contact the security team

Application security

Server-side authorization, CSRF protection, rate limits, input validation and restricted upload handling apply to material workflows.

  • 2FA and session controls
  • Privileged-action confirmation
  • No customer secrets in source control

Data protection

Evidence is private by default; sensitive contact data is encrypted and analytics preferences are respected.

  • Encryption in transit and at rest where configured
  • 90-day pseudonymous scan-event retention
  • Account export and deletion workflows

Report a vulnerability

Send a concise report to support@dppgrid.com with “Security report” in the subject. Do not access other users’ data, disrupt service or disclose a finding before coordinated remediation.

Ready for a concrete next step?

Try the data-readiness assessment, inspect the live demo or talk to the team about your catalogue.

Contact the security team Check readiness