Information Security Policy
Version 1.0 · Effective 9 October 2026 · Next review 9 October 2027
This is Dovri's information security policy. It states how we identify, mitigate and monitor security risks, who is accountable, and what we do when something goes wrong.
This policy applies to every system, device and third-party service that stores or processes Dovri member data, and to everyone who works on Dovri in any capacity. The Founder and Chief Executive Officer of Dovri Technologies LLC is accountable for information security and owns this policy. Dovri Technologies LLC is a Virginia limited liability company and currently has no employees other than the founder; the controls below are sized to that and are extended as the team grows. The policy is reviewed at least annually and whenever there is a material change to the product, a partner, or the regulatory environment.
01Risk management
We maintain a written risk register listing each identified security risk, its likelihood and impact, the control that addresses it, and the person accountable. The register is reviewed quarterly and updated whenever a new system, partner or product capability is introduced.
A risk is added to the register whenever we take on a new third-party service that touches member data, change how money moves, add a new category of data, or learn of a vulnerability affecting a component we use. Each entry is tracked to closure or to an explicit, dated decision to accept the risk.
02Access control
- Every person has a unique named account. Shared logins are not permitted.
- Access is granted on least privilege — the minimum needed for the work, and nothing broader.
- Multi-factor authentication is required on every system that stores or processes member data, and on every administrative console, including hosting, source control, database and payment partner dashboards.
- Credentials are held in a password manager. Secrets and API keys are never committed to source control, never shared over chat or email, and are rotated when a holder's access ends or a key is suspected of exposure.
- Access is removed within 24 hours of a person ceasing work on Dovri.
- Access is reviewed at least annually and whenever responsibilities change.
These controls are set out in full in the Dovri Access Control Policy.
03Protecting data
- All data in transit between clients and servers is encrypted using TLS 1.2 or better.
- All member data at rest is encrypted, including database storage and backups.
- We collect the minimum data needed to run the service and keep it only for the periods set out in the Data Retention and Disposal Policy and the Privacy Policy.
- Bank credentials are never transmitted to or stored by Dovri. Members authenticate with their bank through Plaid, and we receive only the account details required to move money.
- Production data is not copied into development or test environments. Testing uses synthetic data.
04Secure development and vulnerabilities
- Source code is held in a private repository with branch protection on the production branch.
- Automated dependency scanning runs against the codebase and raises alerts for known vulnerabilities in third-party packages.
- Automated secret scanning runs against the repository and its history.
- Workstations and production systems receive security updates automatically and run endpoint protection.
- Vulnerabilities are triaged on discovery. Critical issues are remediated within 7 days, high within 30 days, and medium and low at the next scheduled release.
- Changes affecting authentication, money movement or member data are reviewed before release.
05Third parties
Before a third party is given access to member data we assess its security posture, confirm it is contractually bound to protect that data and to use it only for the service it provides to us, and record it in the risk register. We review that list at least annually and remove access that is no longer needed.
Money movement, identity verification and settlement are performed by regulated partners. Dovri does not hold member funds.
06Monitoring
Application and infrastructure logs record authentication events, administrative actions and money movement. Logs are retained for 13 months. Error and availability monitoring is in place for production systems, with alerts routed to the security contact below.
07Incident response
A security incident is any confirmed or suspected unauthorised access to, disclosure of, or loss of member data, or any event that compromises the integrity of money movement. On discovery we:
- Contain — revoke affected credentials and isolate affected systems immediately.
- Assess — determine what data was involved, how many members are affected, and the root cause.
- Notify — inform affected members, our payment and data partners, and the relevant regulators within the time limits the law and our contracts set. Partner notification obligations are treated as the shortest applicable deadline.
- Remediate — fix the root cause and record the incident, timeline and corrective actions in the risk register.
- Review — conduct a post-incident review and update this policy and our controls where the incident shows a gap.
08Continuity
Member and transaction data is backed up on an automated schedule, backups are encrypted, and restores are tested at least annually. Source code and infrastructure configuration are version-controlled so production can be rebuilt from scratch.
09Reporting a vulnerability
If you believe you have found a security issue in Dovri, email the address below with enough detail to reproduce it. We acknowledge reports within 2 business days and will keep you updated until the issue is resolved.
We will not pursue legal action against anyone who reports a vulnerability in good faith, gives us reasonable time to fix it before disclosing it publicly, and does not access, modify or delete data belonging to anyone else in the course of testing.
Monitored address for vulnerability reports, incident notifications and security questions from partners. For anything else, use support@joindovri.com.