Legal center

Doneven Ventures LLC d/b/a DV Technologies

SECURITY OVERVIEW

Public trust page describing controls that are implemented today

Version 1.0 | Effective Date: January 1, 2026 | Last Updated: January 1, 2026

This page answers common security and privacy questions about the DV Operating System. It is not an independent audit, certification, or attestation. We state only what is implemented. We do not claim certifications we have not earned.

OUR APPROACH

The DV Operating System handles homeowner contact details, recorded conversations, job site photographs, contracts, and financial records. We build on managed infrastructure with security defaults enforced at the data layer, so that a mistake in one screen cannot expose another customer's data.

ARCHITECTURE AND TENANT ISOLATION

  • Every customer operates in a separate organization tenant.
  • Tenant isolation is enforced by row-level security policies in the database itself, not only in application code.
  • Privileged operations run only in verified server-side code paths. Elevated database credentials are never available to the browser.
  • Public-facing endpoints (portal links, webhooks) are separated from authenticated application routes and verify the caller independently.

ACCESS CONTROL

  • Role-based access control with distinct roles for owners, office staff, estimators, field contractors, and platform administrators.
  • Roles are stored in a dedicated table and evaluated by a security-definer database function, so role membership cannot be modified from the client.
  • Administrative capability within a customer's account is limited to users the customer designates as owners.
  • Customers can deprovision an Authorized User at any time, which immediately removes access.

AUTHENTICATION

  • Authentication is managed by a dedicated identity service.
  • Passwords are hashed. We never store plaintext passwords.
  • Leaked-password screening against known-breach corpora can be enabled.
  • Sessions use short-lived access tokens with refresh rotation.
  • Single sign-on is available for eligible plans. Branded per-tenant sign-in links are supported.

ENCRYPTION

  • All traffic is encrypted in transit using TLS.
  • Data at rest, including database records and uploaded files and photographs, is encrypted by our infrastructure providers.
  • Application secrets and third-party API keys are held in a managed secret store and are never committed to source code or exposed to the browser.

PORTAL LINKS

  • Portal access uses single-purpose, revocable tokens rather than shared passwords.
  • Each token scopes access to one client, job, or bid request.
  • Tokens can be revoked by the customer at any time.

LOGGING, AI, AND CALL RECORDINGS

  • Significant record changes are written to an activity log with actor, timestamp, and change detail.
  • AI processing is performed by named third-party model providers listed on our subprocessor page. Those providers are contractually prohibited from using data submitted through the Services to train their own general-purpose models.
  • AI features are designed around human review. Autonomous sending is off by default.
  • Recording and transcription are off unless the customer enables them. Retention is customer-configurable, default twelve months.
  • The customer is responsible for obtaining participant consent. See the AI and Call Recording Disclosure.

RESILIENCE AND INCIDENT RESPONSE

  • Managed database backups with point-in-time recovery on a rolling window not exceeding thirty-five days.
  • Field data capture is offline-tolerant: photographs and notes queue on the device and upload when signal returns.
  • If we confirm a security incident affecting a customer's data, we notify that customer without undue delay and no later than 72 hours after confirmation.
  • Report a suspected vulnerability or incident to security@dvtechnologies.com. We do not pursue legal action against good-faith security research conducted without accessing, altering, or exfiltrating other parties' data and reported privately before disclosure.

SHARED RESPONSIBILITY

We are responsible for platform architecture, tenant isolation, encryption, infrastructure security, secret management, patching, availability, and incident response.

You are responsible for assigning least-privileged roles, deprovisioning departed personnel, protecting credentials and devices, sending portal links only to intended recipients, obtaining consent for recording and messaging, configuring retention, and reviewing AI output before relying on it.

CERTIFICATIONS

We do not currently hold SOC 2, ISO 27001, or any other third-party security certification, and we do not represent that the Services are certified or independently audited. We will update this page if that changes. Nothing on this page is a warranty; the warranty terms in our Terms of Service control.

Security: security@dvtechnologies.com | Privacy: privacy@dvtechnologies.com

© 2026 Doneven Ventures LLC d/b/a DV Technologies. All rights reserved.

legal@dvtechnologies.com | [Principal Place of Business Address], California

This document is maintained by Doneven Ventures LLC d/b/a DV Technologies. It describes our practices and contractual terms. It is not a certification, an audit report, or legal advice.