# Durin security review

Reviewed September 22, 2026.

Public product disclosure. This brief is not an independent audit or certification.

Current pages: [Security](https://getdurin.com/security) · [Trust](https://getdurin.com/trust)

## Security controls

Durin’s governed request path is built around identity, policy, approval, and audit controls. Provider permissions still apply, and production deployments verify the customer-specific path.

### Check who is asking

Requests carry a person or service identity, organization, environment, and connection. Current membership and authority are checked again before execution. WorkOS-backed authentication is implemented, but SSO and MFA enforcement require account-specific verification. A client name alone does not grant access.

### Allow by default. Set stricter rules.

Reviewed requests are allowed by default after identity, connection, resource, and credential checks pass. Administrators can choose default deny, require independent write approval, or deny writes in any environment. Policy decisions and execution outcomes are recorded.

### Approve a specific action

Sensitive writes can require an independent approver. The grant is bound to the requester, connection, exact arguments, resource, and current versions of the tool and policy. It expires and can be consumed once.

### Record decisions and outcomes

Required audit intent is recorded before execution. A policy allowance and a successful write are different facts. If a write may have happened but cannot be confirmed, its outcome stays uncertain rather than being blindly retried. Scoped exports recheck access; checksums do not make records tamper-proof or independently monitored.

## Coverage boundaries

### Through the Durin gateway

- Current identity, organization, and connection checks.
- Default allow, operator-controlled denial, and exact approvals where required.
- Audit intent and a recorded execution outcome.

### Requires separate controls

- Direct API calls, browser actions, shell commands, and clients that bypass Durin.
- Upstream permissions and how an external model provider handles returned data.
- Customer network restrictions and deployment-specific coverage tests.

## Data handling

### Connection credentials

**Scoped implementation**

Connection configuration uses application encryption and scoped execution checks. Credential refresh, revocation, customer-managed keys, and recovery are handled as provider and customer-specific controls.

### Audit records

**Required governance metadata**

The default posture records governance metadata, not a full transcript of prompts and tool results. Retention schedules, deletion, legal hold, and restore are handled through customer-specific operating controls.

### Models and operators

**Explicit data boundaries**

Durin does not host or train AI models. A client can send returned tool results to its model provider. Dedicated tenant resources do not make the SaaS operator cryptographically unable to access data.

## Evidence and production trust

Reviewed September 22, 2026. Durin governs AI-agent access through its MCP gateway. These disclosures cover the controls applied to routed requests and the information available for your security assessment.

### Access control

**Default allow with operator controls**

Reviewed requests are allowed by default after identity, membership, connection, tool, resource, and credential checks. Administrators can choose default deny or require write approval. Decisions and execution outcomes are recorded, and current authority is rechecked before execution. Durin approvals do not expand upstream permissions.

### Approvals and audit

**Action-specific authorization and records**

Where policy permits an approval, it is bound to the requester, connection, exact arguments, resource, and tool and policy versions. Grants expire and are single-use. Required audit intent is recorded before execution; decisions and execution outcomes are recorded separately, including uncertain outcomes.

### Data protection

**Credential encryption and limited capture**

Selected connection and export-destination credentials use AES-256-GCM with authenticated context. Conversation capture defaults to metadata only. Administrators can enable redacted message capture for 1-30 days; that setting does not govern retention of audit, account, or billing records. Durin does not host or train AI models.

### Compliance commitments

**GDPR and PDPA; ISO 27001 alignment**

Marathon Digital Pte Ltd. is committed to meeting applicable GDPR and Singapore PDPA obligations and aligning its security programme with ISO/IEC 27001 principles. These are management commitments, not certification or independent assurance.

### Independent assurance

**Management disclosure**

No SOC 2 attestation, ISO certification, or independent penetration-test result is claimed. The public security brief describes controls and their scope for vendor due diligence; it is not an independent audit report.

## Vendor due diligence

### Review the security brief

Download the control summary, coverage boundaries, and data-handling disclosures for your vendor risk assessment. The brief is available without an account.

### Send your questionnaire

Contact privacy@getdurin.com with your security questionnaire, proposed use case, data categories, and review requirements. Request supporting documentation through the same contact.

### Confirm contractual requirements

Raise data-processing, subprocessor, transfer, residency, incident-notification, and service-level requirements during procurement. Binding commitments must be documented in the applicable agreement.

## Security questions

### Can Durin prevent prompt injection?

Durin does not claim complete prevention. It can restrict permitted tools, resources, and actions and require exact approvals for routed requests. Content inspection has tested limits; it is not a guarantee for every attachment, binary response, or stream.

### Does a Durin approval grant upstream permission?

No. Durin policy and approval do not expand the connected system’s credential permissions. Provider consent, scope, and revocation must be verified separately.

### Does Durin provide end-to-end encryption or bring your own key?

Application encryption is implemented in bounded areas. Customer-managed keys, key recovery, and complete key lifecycle evidence are handled as customer-specific security review topics.

## Vendor review questions

### What documentation is available for vendor due diligence?

The downloadable brief covers security controls, data handling, coverage boundaries, and assurance status. Public architecture, threat-model, API, and MCP gateway documentation can support a technical review. Contact privacy@getdurin.com with your questionnaire and any requests for additional evidence.

### Which activities are covered by Durin’s controls?

Controls apply to requests routed through the Durin gateway. Direct API calls, browser actions, shell commands, and clients that bypass the gateway remain outside that boundary. Customer identity settings, network restrictions, and upstream provider permissions form part of the overall access-control environment.

### Can an external AI provider receive customer data?

Durin does not host or train AI models. An agent client can forward tool results to its model provider, whose data-handling terms apply separately. Durin’s conversation-capture settings do not control what an external client or model provider retains.

### How are data residency and service commitments agreed?

Enterprise is contact sales only and includes All connection features, Tenant isolation, SSO, SCIM directory sync, 99.9% uptime SLA, Support SLA. Uptime and support commitments are defined in your customer agreement. SSO and Directory Sync require an Enterprise organization. Contact sales for pricing. Support response times and coverage are agreed in the customer contract. The public terms alone do not activate these commitments or provide a contractual residency guarantee. Dedicated organization resources do not by themselves establish residency or prevent operator access. Data location, subprocessors, transfers, recovery, and incident-notification requirements belong in the applicable customer agreement.

### How can we raise a security or privacy concern?

Contact privacy@getdurin.com with a description and enough context to identify the affected account or activity. Do not include credentials, access tokens, or sensitive customer payloads in the initial message. This contact does not imply a guaranteed response time.

