Defense in depth
Security overview
Effective 24 August 2026 · Version 1.0
Portal controls
- Fail-closed staff authentication and protected workspace routes.
- Individual accounts with strong password hashing, lockout and forced temporary-password replacement.
- Opaque, hashed server-side sessions with secure, HttpOnly and SameSite cookies.
- Server-side institution and permission evaluation.
- Authentication audit events and session revocation.
Production assurance
Threat modeling, dependency review, vulnerability management, backups, recovery tests, monitoring, incident response and access reviews must be evidenced for each production release.
Responsible disclosure
Report suspected vulnerabilities to security@duruj.io. Do not access customer data, degrade service, use social engineering or publish details before coordinated remediation.
Incident communication
Affected institutions receive incident notices according to the applicable agreement, severity framework and legal obligations. Public status communication must not expose customer or security-sensitive information.
Questions and formal requests
Email compliance@duruj.io for privacy and data-subject matters, or sales@duruj.io for institutional enquiries. Contract notices must use the address specified in the applicable agreement.