# Durin security review

Reviewed September 20, 2026.

Public product disclosure. This brief is not an independent audit or certification.

Current pages: [Security](https://moria.getdurin.com/security) · [Trust](https://moria.getdurin.com/trust)

## Security controls

Durin’s governed request path is built around identity, policy, approval, and audit controls. Provider permissions still apply, and production deployments verify the customer-specific path.

### Check who is asking

Requests carry a person or service identity, organization, environment, and connection. Current membership and authority are checked again before execution. WorkOS-backed authentication is implemented, but SSO and MFA enforcement require account-specific verification. A client name alone does not grant access.

### Start with access denied

A routed request must satisfy the reviewed tool, resource, connection, and policy requirements. Unknown tools, unsupported resources, and missing permissions stay denied. Production writes are denied by the current policy.

### Approve a specific action

Sensitive writes can require an independent approver. The grant is bound to the requester, connection, exact arguments, resource, and current versions of the tool and policy. It expires and can be consumed once.

### Record decisions and outcomes

Required audit intent is recorded before execution. A policy allowance and a successful write are different facts. If a write may have happened but cannot be confirmed, its outcome stays uncertain rather than being blindly retried. Scoped exports recheck access; checksums do not make records tamper-proof or independently monitored.

## Coverage boundaries

### Through the Durin gateway

- Current identity, organization, and connection checks.
- Default-deny policy and exact approvals where required.
- Audit intent and a recorded execution outcome.

### Requires separate controls

- Direct API calls, browser actions, shell commands, and clients that bypass Durin.
- Upstream permissions and how an external model provider handles returned data.
- Customer network restrictions and deployment-specific coverage tests.

## Data handling

### Connection credentials

**Scoped implementation**

Connection configuration uses application encryption and scoped execution checks. Credential refresh, revocation, customer-managed keys, and recovery are handled as provider and customer-specific controls.

### Audit records

**Required governance metadata**

The default posture records governance metadata, not a full transcript of prompts and tool results. Retention schedules, deletion, legal hold, and restore are handled through customer-specific operating controls.

### Models and operators

**Explicit data boundaries**

Durin does not host or train AI models. A client can send returned tool results to its model provider. Dedicated tenant resources do not make the SaaS operator cryptographically unable to access data.

## Evidence and production trust

Reviewed September 20, 2026. Durin governs AI-agent access through its MCP gateway. These disclosures cover the controls applied to routed requests and the information available for your security assessment.

### Access control

**Default-deny authorization**

Requests through Durin are checked against the requester’s identity, organization membership, connection, tool, resource, and policy. Membership and authority are rechecked before execution. Durin approvals do not expand the permissions granted by an upstream provider.

### Approvals and audit

**Action-specific authorization and records**

Where policy permits an approval, it is bound to the requester, connection, exact arguments, resource, and tool and policy versions. Grants expire and are single-use. Required audit intent is recorded before execution; decisions and execution outcomes are recorded separately, including uncertain outcomes.

### Data protection

**Credential encryption and limited capture**

Selected connection and export-destination credentials use AES-256-GCM with authenticated context. Conversation capture defaults to metadata only. Administrators can enable redacted message capture for 1-30 days; that setting does not govern retention of audit, account, or billing records. Durin does not host or train AI models.

### Compliance commitments

**GDPR and PDPA; ISO 27001 alignment**

Marathon Digital Pte Ltd. is committed to meeting applicable GDPR and Singapore PDPA obligations and aligning its security programme with ISO/IEC 27001 principles. These are management commitments, not certification or independent assurance.

### Independent assurance

**Management disclosure**

No SOC 2 attestation, ISO certification, or independent penetration-test result is claimed. The public security brief describes controls and their scope for vendor due diligence; it is not an independent audit report.

## Vendor due diligence

### Review the security brief

Download the control summary, coverage boundaries, and data-handling disclosures for your vendor risk assessment. The brief is available without an account.

### Send your questionnaire

Contact privacy@getdurin.com with your security questionnaire, proposed use case, data categories, and review requirements. Request supporting documentation through the same contact.

### Confirm contractual requirements

Raise data-processing, subprocessor, transfer, residency, incident-notification, and service-level requirements during procurement. Binding commitments must be documented in the applicable agreement.

## Security questions

### Can Durin prevent prompt injection?

Durin does not claim complete prevention. It can restrict permitted tools, resources, and actions and require exact approvals for routed requests. Content inspection has tested limits; it is not a guarantee for every attachment, binary response, or stream.

### Does a Durin approval grant upstream permission?

No. Durin policy and approval do not expand the connected system’s credential permissions. Provider consent, scope, and revocation must be verified separately.

### Does Durin provide end-to-end encryption or bring your own key?

Application encryption is implemented in bounded areas. Customer-managed keys, key recovery, and complete key lifecycle evidence are handled as customer-specific security review topics.

## Vendor review questions

### What documentation is available for vendor due diligence?

The downloadable brief covers security controls, data handling, coverage boundaries, and assurance status. Public architecture, threat-model, API, and MCP gateway documentation can support a technical review. Contact privacy@getdurin.com with your questionnaire and any requests for additional evidence.

### Which activities are covered by Durin’s controls?

Controls apply to requests routed through the Durin gateway. Direct API calls, browser actions, shell commands, and clients that bypass the gateway remain outside that boundary. Customer identity settings, network restrictions, and upstream provider permissions form part of the overall access-control environment.

### Can an external AI provider receive customer data?

Durin does not host or train AI models. An agent client can forward tool results to its model provider, whose data-handling terms apply separately. Durin’s conversation-capture settings do not control what an external client or model provider retains.

### How are data residency and service commitments agreed?

The public terms do not offer a contractual residency guarantee, uptime SLA, or staffed support commitment. Dedicated organization resources do not by themselves establish residency or prevent operator access. Data location, subprocessors, transfers, recovery, and incident-notification requirements should be addressed in the applicable customer agreement.

### How can we raise a security or privacy concern?

Contact privacy@getdurin.com with a description and enough context to identify the affected account or activity. Do not include credentials, access tokens, or sensitive customer payloads in the initial message. This contact does not imply a guaranteed response time.

