Security
How we protect your data
Last updated 27 September 2026
DueBase holds sensitive supplier records and compliance evidence. This page describes, in plain terms, how that data is stored, isolated and accessed. If your security team needs more detail, write to us.
Where your data lives
Your data is stored and processed in Mumbai, India: the application, database, file storage and email delivery all run in that region. The one exception is DueBase AI, described below.
Isolation between organisations
Every record belongs to one organisation. Separation is enforced inside the database itself with row-level security policies, so a query from one organisation cannot return another organisation’s rows even if application code were to ask for them.
Encryption
- All traffic to DueBase is encrypted in transit with TLS.
- The database and file storage are encrypted at rest by our infrastructure provider.
- Passwords are never stored — only a salted, one-way hash is kept.
Access to documents
- Documents are never publicly addressable. Each download uses a signed link that expires shortly after it is issued.
- Links sent to your vendors for uploading are private, time-limited, and can be revoked at any time.
- Vendors see only the items requested from them — never your other vendors, reviews or internal notes.
Accountability
- Uploads, reviews, decisions, approvals and sign-ins are recorded in an audit trail showing who did what, and when.
- Roles control who can administer settings, review, and approve. Approval workflows can require a second person to sign off.
- The audit trail can be exported for your own records or for an inspection.
DueBase AI
When someone on your team runs an AI feature — for example reading a certificate or summarising a report — the relevant document text is sent to our AI processing provider and the result is returned to DueBase. AI output is always a suggestion: nothing is saved to your records until a person reviews and confirms it. AI features only run when a user triggers them.
Sub-processors
We use a small number of carefully chosen providers to run DueBase. Customers can request the full named list.
| Provider | Purpose | Location |
|---|---|---|
| Cloud database and storage provider | Database, sign-in and file storage | Mumbai, India |
| Cloud hosting provider | Runs the DueBase application | Mumbai, India |
| Email delivery provider | Sends service emails, requests and reminders | Mumbai, India |
| AI processing provider | Processes document text for DueBase AI, only when a user runs an AI feature | May be outside India |
Reporting a vulnerability
If you believe you have found a security issue, please email security@duebasehq.com with the details. We will acknowledge your report and keep you informed while we investigate. Please do not access other customers’ data or disrupt the service while testing.