DPRQ
Language
Log inCreate DPP

HomeSecurity & Data Protection

Security & Data Protection

Factual security and data protection controls implemented in DPRQ.

Last updated: 2026-09-03

1. Overview

This page describes security and data protection measures verified in the current DPRQ implementation.

No system can guarantee absolute security. DPRQ does not claim GDPR certification, EU security certification, or 100% security.

2a. Regulatory access tiers (PUBLIC / INTERNAL / RESTRICTED)

  • PUBLIC — fields intended for published passport pages and general disclosure.
  • INTERNAL — organisation operational data (e.g. company contact fields) visible to members, owners, and admins; not published on public passports.
  • RESTRICTED (legitimate interest / authority) — Annex XIII points 2–4 and sensitive B2B documentation. Readable and writable only by organisation owners and admins at the database layer; members and viewers cannot access restricted snapshots or backup JSON.
  • Viewers have read-only access to PUBLIC-tier product data within their organisation; they cannot insert, update, or delete regulatory values, documents, or evidence.
  • Exports (ZIP/JSON/PDF) include only public passport snapshots for non-admin roles; restricted data is never included in public passport exports.

2b. Supplier collaboration access

  • Product owners/admins can invite suppliers via time-limited secure links scoped to specific field keys only.
  • Suppliers do not receive DPRQ accounts, billing access, or visibility into other products or passports.
  • Supplier submissions require owner/admin review before accepted values become authoritative regulatory data.
  • Supplier link creation, submission, and review actions are audit-logged without storing document contents in audit records.

2. Access control and tenant isolation

  • Supabase Auth for user authentication and session management.
  • Email verification required before full dashboard use.
  • Optional multi-factor authentication available in account security settings.
  • Organisation membership roles control access within a customer tenant.
  • PostgreSQL Row Level Security (RLS) policies restrict data access by organisation.

3. Data handling

  • Product, passport, document, and billing metadata stored in Supabase PostgreSQL.
  • Documents and evidence stored in private Supabase Storage buckets.
  • Public passport pages expose only public-tier passport fields intended for publication.
  • Restricted-tier regulatory fields are not published on public passport pages by default.

4. Encryption and transport

  • HTTPS/TLS for data in transit between clients and DPRQ.
  • Provider-managed encryption at rest through Supabase and cloud infrastructure.

5. Integrity and monitoring

  • Application health checks and operational logging.
  • Audit-relevant actions logged with user, entity, and timestamp where implemented.
  • Passport backup and integrity verification features on supported plans.

6. Incident response

DPRQ maintains internal procedures for detecting, investigating, and responding to security and personal data incidents. See internal breach procedure documentation for operator use.

Report suspected security issues to hello@dprqtech.com.

7. Subprocessors

See /subprocessors for infrastructure and payment providers used to deliver DPRQ.

Cookies and storage

DPRQ uses necessary cookies for secure login and consent storage. We use a preferences cookie to remember your language. We do not use analytics or marketing cookies. See our Cookie Policy and Privacy Notice.

Cookie Settings

Choose which optional storage categories you allow. Necessary cookies cannot be disabled.

Necessary
Preferences
Analytics

Not used by DPRQ.

Marketing

Not used by DPRQ.