Access
- Ten roles, each granted capabilities rather than checked by name
- Multi-factor authentication with single-use recovery codes
- Sessions end after 30 minutes idle or 8 hours, and can be revoked
- Sensitive actions ask you to confirm it is you again
Security & trust
Customers, auditors and regulators rely on what DoveSure says. So the record is append-only, every change is chained, and nobody, including DoveSure’s own AI, gets more authority than they should.
Evidence, test results and approvals are never edited or deleted. A correction is a new record.
Every material change is chained. Your auditor can verify the whole chain from the browser.
People can self-attest or upload. Stronger provenance is only ever assigned by the system.
Row-level security in the database keeps each organisation’s data separate, and it is tested on every change.
Argon2id password hashing, multi-factor authentication, recovery codes and server-side sessions.
Who did what, when and why, including every action Dove takes on your behalf.
Provenance
Every piece of evidence records how it was produced. A person can self-attest or upload; the stronger levels are assigned by the system, never claimed.
Know what you are responsible for, control whether it works, and prove it to anyone who asks.