durin
Sign up

Security for your vendor review.

Assess Durin’s access controls, data handling, and compliance commitments for your third-party risk review. Download the security brief or contact us with your questionnaire.

Download security reviewReview security controlsPublic review brief · Markdown · No account required

Controls, scope, and assurance.

Reviewed September 20, 2026. Durin governs AI-agent access through its MCP gateway. These disclosures cover the controls applied to routed requests and the information available for your security assessment.

Access control

Default-deny authorization

Requests through Durin are checked against the requester’s identity, organization membership, connection, tool, resource, and policy. Membership and authority are rechecked before execution. Durin approvals do not expand the permissions granted by an upstream provider.

Approvals and audit

Action-specific authorization and records

Where policy permits an approval, it is bound to the requester, connection, exact arguments, resource, and tool and policy versions. Grants expire and are single-use. Required audit intent is recorded before execution; decisions and execution outcomes are recorded separately, including uncertain outcomes.

Data protection

Credential encryption and limited capture

Selected connection and export-destination credentials use AES-256-GCM with authenticated context. Conversation capture defaults to metadata only. Administrators can enable redacted message capture for 1-30 days; that setting does not govern retention of audit, account, or billing records. Durin does not host or train AI models.

Compliance commitments

GDPR and PDPA; ISO 27001 alignment

Marathon Digital Pte Ltd. is committed to meeting applicable GDPR and Singapore PDPA obligations and aligning its security programme with ISO/IEC 27001 principles. These are management commitments, not certification or independent assurance.

Independent assurance

Management disclosure

No SOC 2 attestation, ISO certification, or independent penetration-test result is claimed. The public security brief describes controls and their scope for vendor due diligence; it is not an independent audit report.

Support for your due diligence.

  1. Review the security brief

    Download the control summary, coverage boundaries, and data-handling disclosures for your vendor risk assessment. The brief is available without an account.

  2. Send your questionnaire

    Contact privacy@getdurin.com with your security questionnaire, proposed use case, data categories, and review requirements. Request supporting documentation through the same contact.

  3. Confirm contractual requirements

    Raise data-processing, subprocessor, transfer, residency, incident-notification, and service-level requirements during procurement. Binding commitments must be documented in the applicable agreement.

What to establish in your security review.

What documentation is available for vendor due diligence?

The downloadable brief covers security controls, data handling, coverage boundaries, and assurance status. Public architecture, threat-model, API, and MCP gateway documentation can support a technical review. Contact privacy@getdurin.com with your questionnaire and any requests for additional evidence.

Which activities are covered by Durin’s controls?

Controls apply to requests routed through the Durin gateway. Direct API calls, browser actions, shell commands, and clients that bypass the gateway remain outside that boundary. Customer identity settings, network restrictions, and upstream provider permissions form part of the overall access-control environment.

Can an external AI provider receive customer data?

Durin does not host or train AI models. An agent client can forward tool results to its model provider, whose data-handling terms apply separately. Durin’s conversation-capture settings do not control what an external client or model provider retains.

How are data residency and service commitments agreed?

The public terms do not offer a contractual residency guarantee, uptime SLA, or staffed support commitment. Dedicated organization resources do not by themselves establish residency or prevent operator access. Data location, subprocessors, transfers, recovery, and incident-notification requirements should be addressed in the applicable customer agreement.

How can we raise a security or privacy concern?

Contact privacy@getdurin.com with a description and enough context to identify the affected account or activity. Do not include credentials, access tokens, or sensitive customer payloads in the initial message. This contact does not imply a guaranteed response time.

Discuss your security requirements.

Send your questionnaire or documentation request to privacy@getdurin.com. Include your proposed use case and the requirements your security and procurement teams need to assess.

Contact security

Production connections use provider setup and trust review.