Trust & Security

Security and governance, built in — not bolted on.

DBLU is designed for organizations that need AI to be accountable. Tenant isolation, human approval, and full audit trails are foundational to the platform, not afterthoughts.

How DBLU keeps your knowledge safe

Six security and governance pillars define how DBLU protects organizational knowledge and ensures AI is trustworthy.

Tenant isolation

Every organization's data is isolated by Row-Level Security on all entities and server-side authorization in every org-scoped backend function. Customers cannot access another organization's data through any interface.

Role-based access

Access is governed by platform role and organization membership, resolved server-side. Client-supplied roles are never trusted. Internal operations are restricted to platform staff.

Human approval

Inferred facts require human approval before entering your structured operational model. Publication to the runtime requires validation and human sign-off, with full audit of every decision.

Versioned & rollback-ready

Published knowledge is versioned. Every package records before/after runtime versions and supports rollback. Drift between consulting knowledge and the runtime is detected and surfaced for review.

Audit trails

Lifecycle transitions, reasoning history, publication events, approval decisions, and outcome checkpoints are all recorded for traceability and accountability.

No privilege escalation

Role switching is server-authorized and rejects escalation. The platform role and organization membership cannot be set by the client.

Why this matters

Governance by design means authority, approval, oversight, and security are built into every recommendation from the beginning — not added after implementation. And the business context that makes AI effective stays under your organization's control: your context, your control.

Responsible disclosure

Report a security concern

If you believe you have identified a security vulnerability or have a security concern, please contact our team through the contact page with details. We take all reports seriously and will investigate promptly.

Security commitments

  • Tenant isolation enforced at the data layer and the API layer
  • Server-side authorization on every org-scoped operation
  • Human approval required before knowledge becomes operational
  • Versioned publication with rollback and drift detection
  • Audit trails across the full engagement lifecycle