Security & Data Handling

How DVLP Studio
handles your data.

DVLP Studio is a software studio. We follow the security practices used by the companies that handle sensitive data well — Stripe, Linear, Notion — and we are clear about what we do and don't yet have in place.

Core principle

Your data is yours.

We never sell your data. We never train our models on your data. We never share your data with any third party except the infrastructure providers required to run the service. Each firm's data lives in its own isolated database — no cross-firm access, ever.

Encryption

Encrypted at rest. Encrypted in transit.

Data is encrypted with AES-256 at rest. All connections use TLS 1.3 in transit. Database credentials are encrypted with a separate key. Documents uploaded to the product are stored in encrypted object storage and accessible only through authenticated, audit-logged requests.

Infrastructure

US-based infrastructure. Named vendors.

We use Supabase (Postgres, storage, auth) and Vercel (application hosting) for the core product, both running on AWS in US regions. For enterprise customers, we offer a dedicated AWS deployment in your chosen region. We do not use vendors who train AI models on customer data.

Access control

Only your team. Always audit-logged.

Each user authenticates with their own credentials. Roles control what each user can see and do. Every access to documents and every query is recorded in an audit log that admins can review. DVLP staff do not access customer data except when explicitly requested for support, and those sessions are recorded.

AI providers

No model training on your data.

We use Anthropic Claude and OpenAI for language model inference. Both providers offer zero-data-retention API endpoints that we use exclusively. Your data is sent to these APIs only to answer your queries — never to train models, never retained on the provider's side beyond the request.

Where we are today

Honest about the current state.

DVLP Studio is a small team building production software. We follow industry-standard security practices but we are not yet SOC 2 or HIPAA certified. We are building toward formal certifications as our customer base grows. Enterprise customers requiring specific compliance can work with us on a dedicated deployment.

Security questions

Talk to us before your IT review.

For security questions, IT reviews, or specific architecture details for your firm, contact us directly. We answer within one business day.

support@dvlpstudio.com