Security & trust
dlogs is privacy-first and security-first from day 1. We build durable decision history with append-only, tamper-evident records and strong integrity controls. That is the ceiling of trust language we claim on this site — we do not advertise SOC or compliance certifications.
- Webhook deliveries are signature-verified and idempotent before processing.
- Decision records are append-only and tamper-evident per organization.
- OAuth callbacks use one-time state validation to prevent replay.
- Advisory GitHub status checks are published with observable event logs.
- API keys can be created, rotated, and revoked from product settings.
Integrity approach
- Build secure defaults into product and infrastructure decisions.
- Maintain verifiable audit trails and operational transparency.
- Keep advisory GitHub checks non-blocking by design.
Questions about security posture or vendor review? Contact hello@dlogs.app.