Access Control Policy

Version 1.0 · Effective 9 October 2026 · Next review 9 October 2027

This policy states who may access Dovri systems and member data, how that access is granted and authenticated, and how it is changed, reviewed and removed. It sits under the Dovri Information Security Policy and expands its access control section.

Scope and ownership

This policy applies to every account, credential and key that can reach a Dovri production system or member data — human or machine — and to everyone who works on Dovri in any capacity. The Founder and Chief Executive Officer of Dovri Technologies LLC is accountable for access control and owns this policy. Dovri Technologies LLC is a Virginia limited liability company and currently has no employees other than the founder; where a control below describes handling a departure or transfer, it applies from the first time a person's access changes. This policy is reviewed at least annually and whenever responsibilities, systems or partners change.

01Named accounts

02Least privilege

Access is granted at the minimum level needed to do the work, and no broader. Where a provider offers scoped permissions, the narrowest scope that satisfies the need is used rather than a general administrative role.

03Authentication

04Machine and service credentials

Systems authenticate to one another with tokens and certificates, not with human accounts.

05Member authentication

Members authenticate to Dovri before they reach any screen that moves money or links a bank account.

06Granting, changing and removing access

07Review

Access is reviewed at least annually and whenever responsibilities, systems or partners change. A review lists every account and key that can reach production or member data, confirms each is still needed at the level it holds, and removes or reduces the rest. The outcome is recorded with the date and what changed.

Authentication events and administrative actions are logged and retained for 13 months, so access can be reconstructed after the fact.

08Exceptions and enforcement

Any departure from this policy requires a recorded, dated decision by the policy owner stating the reason, the compensating control and the date the exception ends. Exceptions are revisited at each review.

Access granted outside this policy is withdrawn on discovery, and the circumstances are recorded in the risk register.

Security contact
security@joindovri.com

This policy sits under the Dovri Information Security Policy. Data handling and retention are covered in the Privacy Policy.

Back to dovri