SECURITY & TRUST

Your Brain holds your company's most valuable knowledge. Here's how we treat it.

Duet asks for real trust: your strategy, your positioning, your institutional knowledge. This page explains, in plain language, exactly how that data is handled, who can see it, and what we're building next. If your security team has questions we haven't answered, we'll get them answers: scott@letsduet.ai.

Your data stays yours.

You own your Customer Content and your Brain, full stop. We use it only to provide the service to you. We never use your Content to train foundation models, and we never use one customer's Brain to improve another customer's outputs or Twins. Your Brain makes your workspace smarter. It is not pooled, shared, or mined.

How AI processing works.

When you work in Duet, your prompts and the relevant context from your Brain are processed by leading AI model providers, currently Anthropic (Claude) and OpenAI, to generate your outputs. Our agreements with these providers prohibit them from training on your data.

Workspace isolation.

Every customer's workspace and Brain is logically isolated. Access is authenticated, role-based within your team, and logged.

When humans see your data.

Duet has humans in the loop by design, so we're explicit about access. HITL operators and agencies see only the workspaces that engaged them, only for the duration of the engagement, under confidentiality obligations, with access logged. Duet's own team accesses customer data only for support you request or to investigate security issues, never to browse. And the experts behind Digital Twins do not see your data at all: your context is applied to their Twin inside your workspace, not sent to the human.

Encryption and infrastructure.

Data is encrypted in transit (TLS 1.2+) and at rest (AES-256). Duet runs on Amazon Web Services infrastructure in the United States, with Supabase for database infrastructure. Backups are encrypted and expire on a fixed schedule.

What we're building next.

We're early, and we're building our compliance posture in the open. On the near-term roadmap: SOC 2 certification, SSO/SAML, granular audit logs, and admin controls for larger teams. If your organization has specific requirements, tell us; design partners are shaping this roadmap now.

Frequently asked questions

Have a security questionnaire?

Send it over: scott@letsduet.ai