Trust Center
Last updated: August 16, 2026
The Dureach Trust Center gives customers, buyers, partners, and auditors one place to review our legal terms, data protection posture, security controls, risk profile, and document-request workflow. It separates public website terms from customer SaaS terms, DPA commitments, acceptable-use rules, and trade-data licensing terms.
Start with the right trust document
| Document | Use it for | Link |
|---|---|---|
| Website Terms of Use | Public website browsing, public content, forms, and website conduct | Website Terms of Use |
| Customer SaaS Terms | Accounts, subscriptions, workspaces, AI agents, APIs, support, and customer content | Customer SaaS Terms |
| Data Processing Addendum | Customer personal data processed by Dureach as a processor or service provider | Data Processing Addendum |
| Acceptable Use Policy | Prohibited activity across website, SaaS, API, AI workflow, outreach, and data services | Acceptable Use Policy |
| Trade Data Licensing Terms | Customs, shipment, company, professional, enrichment, and B2B data products | Trade Data Licensing Terms |
| Privacy Policy | Personal information practices, privacy rights, cookies, transfers, retention, and contacts | Privacy Policy |
| Remove My Data Policy | Requests to remove or suppress personal data where applicable | Remove My Data Policy |
| Attribute Data Directory | Business-context data categories used in Dureach services | Attribute Data Directory |
Signed agreements, order forms, and negotiated addenda control where they conflict with public website terms.
Certification and assurance profile
Dureach separates public policy documents from gated assurance artifacts. Public pages are available without an NDA. Detailed audit evidence, reports, and customer-specific security questionnaires may require a qualified business review and NDA.
| Artifact | Status | Access path |
|---|---|---|
| SOC 2 Type II attestation | Listed as Dureach’s active third-party SaaS control attestation | Request through the document workflow below |
| Security overview | Available for procurement and vendor-risk review | Request from [email protected] |
| Data Processing Addendum | Public | Data Processing Addendum |
| Privacy Policy | Public | Privacy Policy |
| Acceptable Use Policy | Public | Acceptable Use Policy |
| Trade-data licensing terms | Public | Trade Data Licensing Terms |
| Subprocessor information | Available for customer review | Request from [email protected] |
| Penetration-test executive summary | Available when a current shareable summary exists | Request through security review |
| Insurance certificate | Available for qualified enterprise procurement | Request from [email protected] |
| Security questionnaire response | Available for qualified enterprise procurement | Send questionnaire to [email protected] |
Dureach does not claim certifications on this page unless they are listed above or confirmed in a signed customer package.
Risk profile for enterprise review
| Area | Dureach posture |
|---|---|
| Service category | B2B SaaS for governed AI workflows, workspace operations, APIs, enrichment, and trade-data workflows |
| Primary users | Founders, GTM teams, agencies, RevOps, operators, and customer-authorized workspace users |
| Typical data handled | Account data, user activity, customer content, business contact records, workflow metadata, support records, and trade-data signals |
| Sensitive data stance | Not intended for protected health information, payment-card data, government IDs, children’s data, biometric data, or other sensitive regulated data unless a signed agreement permits it |
| AI governance | Operator review is required before customer-facing, regulated, legal, financial, employment, customs, or high-impact use of outputs |
| Data role | Dureach may act as processor/service provider for customer personal data and independent controller for website, account, security, billing, and certain business-data operations |
| Hosting and infrastructure | Cloud-hosted service using managed infrastructure, access controls, logging, backup processes, and vendor review |
| Encryption | TLS is used for data in transit; encryption at rest is used where supported by production systems and managed providers |
| Access management | Workspace permissions, least-privilege operational access, credential controls, and administrator responsibility for user access |
| Vendor risk | Subprocessors and service providers support hosting, security, analytics, communications, billing, support, and workflow operations |
| Business continuity | Backup, incident response, and operational monitoring practices support service recovery and customer notification workflows |
| Compliance boundaries | Dureach does not provide legal, tax, customs, financial, employment, medical, credit, or regulated-decision advice |
Security controls overview
Dureach uses administrative, technical, and organizational safeguards designed to protect customer information and service integrity.
| Control domain | Practice summary |
|---|---|
| Access control | Role-based workspace access, administrator-managed users, credential protection, and least-privilege operational access |
| Data protection | Encryption in transit, encryption at rest where supported, backup practices, and restrictions on sensitive data uploads |
| Secure operations | Logging, monitoring, vulnerability handling, vendor review, and incident-response procedures |
| AI workflow governance | Human approval checkpoints, customer-owned prompts and files, output review expectations, and prohibited high-impact use cases |
| Privacy governance | DPA terms, privacy-rights intake, retention practices, transfer safeguards, and suppression/removal processes |
| Abuse prevention | Acceptable-use rules, anti-abuse monitoring, API key controls, export restrictions, and suspension rights for risky activity |
Request security and compliance documents
Qualified customers, enterprise buyers, auditors, and partners can request gated security and compliance documents.
- Prepare the request. Include your company name, business email, Dureach workspace or sales contact, requested documents, review deadline, NDA status, and procurement system link if available.
- Send the request. Use
[email protected]for security artifacts and questionnaires,[email protected]for DPA/subprocessor/privacy requests, and[email protected]for contract, insurance, or licensing requests. - Complete access review. Dureach may verify the business relationship, confirm scope, require an NDA, or route the request to the right owner.
- Receive the package. Approved requests may receive a secure link, completed questionnaire, public policy references, or a scoped response.
- Refresh when needed. For annual vendor reviews, request refreshed documents at least 30 days before your internal deadline.
Privacy and data governance
Dureach provides workflow software and related services for teams using research, outreach, publishing, website, CRM, data, and operator-reviewed AI execution workflows.
Depending on the workflow, Dureach may process account information, workspace activity, customer content, business contact data, trade-data signals, support records, and user-provided inputs needed to operate the service.
Privacy requests can be sent to [email protected]. Security concerns can be sent to [email protected].
Service status and incident contact
Operational status information is available at https://dureach.com/uptime.
For urgent abuse, security, or legal escalations, use the contacts below.
Contacts
- Privacy: [email protected]
- Security: [email protected]
- Abuse: [email protected]
- Legal: [email protected]