Security and governance, built in — not bolted on.
DBLU is designed for organizations that need AI to be accountable. Tenant isolation, human approval, and full audit trails are foundational to the platform, not afterthoughts.
Six security and governance pillars define how DBLU protects organizational knowledge and ensures AI is trustworthy.
Tenant isolation
Every organization's data is isolated by Row-Level Security on all entities and server-side authorization in every org-scoped backend function. Customers cannot access another organization's data through any interface.
Role-based access
Access is governed by platform role and organization membership, resolved server-side. Client-supplied roles are never trusted. Internal operations are restricted to platform staff.
Human approval
Inferred facts require human approval before entering your structured operational model. Publication to the runtime requires validation and human sign-off, with full audit of every decision.
Versioned & rollback-ready
Published knowledge is versioned. Every package records before/after runtime versions and supports rollback. Drift between consulting knowledge and the runtime is detected and surfaced for review.
Audit trails
Lifecycle transitions, reasoning history, publication events, approval decisions, and outcome checkpoints are all recorded for traceability and accountability.
No privilege escalation
Role switching is server-authorized and rejects escalation. The platform role and organization membership cannot be set by the client.
Governance by design means authority, approval, oversight, and security are built into every recommendation from the beginning — not added after implementation. And the business context that makes AI effective stays under your organization's control: your context, your control.
Report a security concern
If you believe you have identified a security vulnerability or have a security concern, please contact our team through the contact page with details. We take all reports seriously and will investigate promptly.
Security commitments
- Tenant isolation enforced at the data layer and the API layer
- Server-side authorization on every org-scoped operation
- Human approval required before knowledge becomes operational
- Versioned publication with rollback and drift detection
- Audit trails across the full engagement lifecycle