Trust Center
Know the work was done — and know how that record is protected
DutySeal builds a verifiable operational record for every shift: who did what, when, where, with what proof, what the result was, and what happens next when it isn’t done. This page explains how we protect customer data today, which providers help us run the stack, and how enterprise buyers can evaluate us — calmly, without hype.
We label controls asCurrentPartialorRoadmap— roadmap items are never presented as done.
DutySeal-led
How we secure data
A clear view of what is in place today, what is still maturing, and what is planned — without overclaim.
Tenant and accessPartial
Access is scoped to your organization and locations. Managers, floor roles, and vendor access (where enabled) follow role-based permissions. We will publish the confirmed RBAC matrix as controls mature — we will not invent the matrix here.
AuthenticationPartial· MFARoadmap
DutySeal’s web app uses platform authentication (Supabase Auth) for sign-in, sign-up, and password reset. Multi-factor authentication is not offered today — MFA is on the trust roadmap, not a current control.
AuthorizationPartial
Authorization combines application roles with database controls, including row-level security (RLS) on core org-scoped tables, with least-privilege intent. Coverage is broad with known hardening still in progress. We do not claim perfect tenant isolation.
Operational record / audit trailCurrent
DutySeal keeps an operational evidence trail — assign, verify, document, follow through — with evidence packets and manager-gated audit export in product. We still do notclaim WORM or cryptographic immutability.
Separation of systemsCurrent
DutySeal owns the ops record. Catalog, inventory, and books live in Root Tempo. Shopping and Concierge live in StoreTempo. Peers connect over HTTP — not one shared monorepo database.
Secrets and environmentsPartial
The browser client uses publishable anon keys only; service credentials stay server-side. We do not claim a formal secrets vault or rotation runbook on this page.
Providers
Subprocessors
Known providers that help us run the stack. We update this list when vendors change. Enterprise buyers may request the current list under NDA.
Partial
| Subprocessor | Role | Products (known) |
|---|---|---|
| Supabase | Auth, database, realtime/edge where used | DutySeal, Epi-Tracker |
| Stripe | Payments / billing | DutySeal, StoreTempo, Epi-Tracker (as applicable) |
| Twilio | Optional SMS notifications | DutySeal (when enabled) |
| Nominatim | Geocoding | DutySeal |
| StoreTempo / Root Tempo | Peer federation (HTTP) | Connected ops / commerce / books |
| Hosting / CDN | App and marketing hosting | Per product — legal names and regions confirmed before we publish them here |
| Email / messaging | Transactional mail (non-SMS) | Vendor TBD — not listed until confirmed |
Controls
Encryption
- In transitCurrentTLS for web and app traffic.
- At restPartialProvider-managed encryption for databases and storage (Supabase / host). Confirmed project settings and provider-doc links publish after inventory — not before.
- DevicesPartialMobile apps (DutySeal Flutter; Epi-Tracker) follow OS secure-storage patterns where applicable — confirmed before any broader claim.
- Customer-managed keys / BYOKRoadmapNot offered today.
Controls
Access control
- RolesPartialOrg- and location-scoped roles for DutySeal (managers, floor, vendor portal where enabled). Full detail follows the RBAC inventory.
- Admin / support accessPartialRoadmapProduction access is intended to be limited and logged; formal policy and IR runbook land in the trust plan.
- MFARoadmapNot available today.
- SSORoadmapSAML/OIDC for Enterprise is planned — not live until it ships.
Data
Retention and export
What ships todayPartial
Manager-gated audit export packets and payroll CSV export exist in DutySeal. Full subject-access / GDPR-style personal-data packages and complete erasure (including Auth account + storage purge) arenot claimed as complete.
Backups / PITRRoadmap
We rely on cloud-provider defaults until we publish RPO/RTO and retention policy —no backup SLA claimed here.
Until a public retention/deletion policy is live: contactsupport@dcsma.com. DPA draft available via the same address until counsel clears a definitive version; executed DPA then applies. Epi-Tracker family data handling follows the product privacy path (epi-tracker.com/privacy) as legal copy is completed — we do not invent HIPAA coverage.
Incidents
Incident response
PartialRoadmap
We investigate suspected security incidents, contain impact, and notify affected customers as required by law and contract. Security contact:support@dcsma.com. Formal IR runbook and tabletop exercises areRoadmapon the 90-day trust plan. We will not overstate maturity.
Guardrails
Product guardrails
DutySealCurrent
Operational execution for the shift: assign, track, verify, document, follow through. Photo proof and corrective actions are your operational data. DutySeal is not a POSand not a task-list substitute. Money stays in systems built for money.
Root TempoCurrent
Catalog, inventory, and books system of record. Federates facts to peers over HTTP.
StoreTempoCurrent
Grocery commerce experience — one store map, Guided Shopping and Personal Concierge. Payments via Stripe where used.
Epi-TrackerCurrent
Helps families keep a life-saving kit with the person who needs it (leave-behind alerts, Hand off, Watching). Not a medical device. Not a diagnosis tool. We do not invent care-plan steps; check-in and emergency help stay under the family’s own plan. We donot claim HIPAA unless a Business Associate Agreement path is explicitly in place.
Canna Seed to SaleRoadmap
Seed-to-sale compliance framing for licensed operators — in development; no overclaim of regulator connectivity until real.
Roadmap
What’s live vs what’s next
High-level trust plan. Items in Later columns are ROADMAP until they ship — never described as done.
| Now (Days 1–30) | Next (31–60) | Then (61–90) |
|---|---|---|
| Trust outline + FAQ · Controls inventory · MSA/DPA templates (counsel) · Cyber insurance cert if available | DutySeal pen test + fix P0/P1 · Admin audit log + RBAC doc · Retention/export policy published · Trust page live | SSO on Enterprise · SOC 2 Type I kickoff · Questionnaire vault · IR tabletopRoadmap |
Hard stop: SSO, SOC 2, and pen-test results areRoadmapuntil they exist — never described as done.
FAQ
Security FAQ
Who is DCSMA?
DCSMA builds enterprise software ecosystems that solve real operational problems. DutySeal is our operational execution platform — the shift record so managers can say “show me” instead of reconstructing yesterday.
Where is DutySeal data hosted?Partial
Application data for DutySeal’s live app is stored with our cloud database provider (Supabase). Marketing/CMS hosting may differ by product. Exact regions and project settings are confirmed before this answer is published as final.
How do you isolate customers?Partial
Access is scoped to the customer’s organization and locations. Authorization combines application roles with database controls (RLS where enabled). Full RBAC detail follows our controls inventory.
Do you encrypt data?CurrentPartial
Yes in transit (TLS). At rest, encryption is provided by our infrastructure vendors (e.g. Supabase). We do not invent key-management or BYOK claims. Backup/PITR specifics areRoadmapuntil documented.
Who are your subprocessors?Partial
Primary known providers: Supabase (auth/database), Stripe (payments), and web hosting per product. This Trust page carries the current list; enterprise buyers may request it under NDA. We do not invent email or CDN vendors here.
Are you SOC 2 certified?Roadmap
Not certified today. SOC 2 evidence habits and Type I kickoff are on the 90-day plan. Until then we share architecture, policies-in-progress, and questionnaire answers — never “SOC 2 done.”
Do you support SSO / MFA?Roadmap
Neither MFA nor SSO is available on DutySeal today. SSO is on the later trust roadmap. We will not list either as available until they ship.
Can we export or delete our data?Partial
Today: manager-gated audit export packets and payroll CSV export. Full subject-access packages and complete account/storage erasure are still maturing — not claimed as complete. Retention/backup policy isRoadmap. Emailsupport@dcsma.com; DPA applies when executed.
How do you handle incidents?PartialRoadmap
We investigate, contain, and notify as required. Formal IR runbook and tabletop are scheduled in the trust plan. Contactsupport@dcsma.com.
Is DutySeal in PCI scope?Current
DutySeal is an operational record, not a payment application. Card payments (where used) go through Stripe; we do not intend to store cardholder data. Scope is reviewed with counsel as features change.
Does Epi-Tracker create HIPAA or medical-device obligations?Current
Epi-Tracker is not a medical device andnot a diagnosis tool. It supports family leave-behind and Watching workflows under the family’s own plan. We do not claim HIPAA compliance unless a Business Associate Agreement path is explicitly in place.
How do Root Tempo and StoreTempo relate for security?Current
They are peer systems connected over HTTP — catalog/commerce versus the ops record — not one shared database. Enterprise reviews can be product-by-product; DutySeal is the first deep trust narrative because it holds the shift evidence trail.
Can we get an MSA / DPA?Partial
Yes. Path locked: template-first, then counsel review. Sales shares templates for discussion; nothing is final until counsel clears. Unsigned drafts are not the contract. Request viasupport@dcsma.com.
Do you run penetration tests?Roadmap
Vendor shortlist/schedule is in progress; first DutySeal pen test is planned next. Pen tests are not completed today. Results (when they exist) are shared under NDA after critical remediation.
Who do we contact for security review?
support@dcsma.com— Sales can route questionnaires meanwhile.
Questions about security or a DPA?
Security contact:support@dcsma.com. MSA / DPA: template-first, then counsel review — not published as final until counsel clears. DPA link lands when executed.
Hub: dcsma.com/trust· Privacy (per product when published) · Terms · Last updated 2026-09-07