The Job record
Job events are append-preserved. A correction adds a superseding entry rather than silently overwriting the earlier event, so participants can inspect how the record changed.
Contributions carry their producer and time. The record distinguishes a person's observation or attestation from a document, instrument reading, or AI proposal.
Access is checked on every request
Requests to read or change a Job are evaluated against the current participant and their role. Possessing an identifier is not treated as permission. Unauthorized callers do not receive details that distinguish a Job they cannot access from one that does not exist.
Media and the AI boundary
Raw media is sent to the current AI provider only after a user starts an operation that requires it. Simply viewing media does not send it to a model.
Dowelify currently calls the OpenAI API with store: false. OpenAI states that API data is not used to train models by default, while limited provider retention can still occur for security, abuse monitoring, or legal obligations. Dowelify does not claim Zero Data Retention.
Nothing in an uploaded manual, document, or transcript can change who has access; permissions are enforced outside the model.
Human authority is enforced by the application.
AI output remains a proposal. In the current application, recording work as performed, accepting completed work, and releasing something back into service require an authorized person's explicit action.
This prevents a fluent model response from becoming a false claim that physical work occurred or was approved. It does not guarantee that a person's decision is correct; safety still depends on qualified human judgment, applicable rules, and the physical evidence.
Sessions and controlled change
Participants use signed, expiring sessions rather than a public or shared credential. Changes to the system follow a versioned, reviewable path, and access rules are enforced by the service—not trusted to what a screen happens to show.
Current assurance scope
The safeguards above are current controls. Independent certification and the following broader operational assurances are outside the current scope.
- We do not hold SOC 2, ISO 27001, or another third-party security certification.
- We do not yet claim routine, scheduled, media-complete production backups with a tested restore cadence.
- We do not yet offer automated whole-account export or deletion; verified pilot requests are handled manually.
- Structured Job records persist. Long-term private-media storage remains in development and is not presented as an enabled public capability.
Report a vulnerability
Send enough detail to reproduce a suspected security problem to security@dowelify.com. We will acknowledge a report within three business days, keep the reporter informed as we investigate, and not pursue good-faith research conducted without harming people, accounts, or data.
Please do not access another person's information, degrade the service, or publish an unresolved issue before we have had a reasonable opportunity to investigate.

