Doux
Security

Your research happens
inside your own walls.

Doing the looking means going into the systems that hold your book — the management system, the mailbox, the carrier portals. So the whole question is where that walking happens, and who can see it. The answer is: in your own isolated instance, against your own credentials, which never leave your environment. Nothing about your book is pooled with another agency's, and every step is written down.

The model never executes anything itself. It proposes; a deterministic layer decides and acts. You get the capability without having to become a security engineer.

Isolated per tenant · your credentials never leave your environment · every action on the record · pending SOC 2 Type I certification

Posture, as it stands today

Where the product
actually is.

The architecture and the formal compliance work are on one list below, so your IT lead and your carrier's vendor questionnaire get the same answer. Anything not on the list is not in place yet.

Pending SOC 2 Type I certification
Credentials never leave your environmentCarrier, portal and mailbox credentials stay in your tenant. We hold no copy.
The model never executesIt proposes an action from a closed list. A deterministic layer decides and acts.
Irreversible actions need a personAnything that leaves the agency or cannot be undone waits for a named human approval.
Claude vs Doux

Built on Claude.
Hardened for an agency.

Claude is the foundation Doux runs on, and you can run it yourself. Doing so hands you full control — and with it, full responsibility for the isolation, the guardrails and the audit trail. Doux ships that same foundation already fitted to a commercial P&C agency, with the boundaries built in.

Doux ships this foundation already fitted to a commercial P&C agency. Anything still in progress is named on this page, in plain sentences.

Defence in depth

Every layer, on purpose.

Each card below has the plain-English version on top and the mechanism underneath.

Your credentials stay yours

Tenant-held secrets

The logins for your management system, your carrier portals and your mailbox live in your own tenant environment. We do not hold a copy, and no other tenant's instance can reach them.

Under the hood
  • per-tenant secret store, separate keys
  • no shared credential pool across tenants
  • secrets stripped from logs and API responses

The model proposes, it never executes

Deterministic action layer

The language model emits a label from a closed list of permitted actions. It never writes a command, never names a recipient, and never touches your systems directly. A deterministic router decides what actually happens.

Under the hood
  • closed enum of action keys, not free text
  • the router owns every address and destination
  • an unrecognised label fails closed

Irreversible actions wait for a person

Approval gate

Anything that leaves the agency, changes coverage, or cannot be undone stops and asks a named human. Approval is checked against a roster — not against a field that merely contains a name.

Under the hood
  • approver checked against an allow-list, failing closed
  • approval recorded with who, what and the evidence shown
  • rules you author yourself decide what is routine

Every action is on the record

Append-only audit

What was done, by which agent, on what evidence, and who approved it. Entries are appended and chained — an earlier entry cannot be quietly rewritten later.

Under the hood
  • hash-chained entries, append-only
  • actor, action, target, outcome on every state change
  • queryable for an audit or an E&O question

Writes are read back

Verify-after-write

Management systems can commit a record and then fail while answering. Doux never treats an error as a failed write — it reads the record back and confirms the real end state before reporting anything as done.

Under the hood
  • no blind retry on an ambiguous response
  • state re-read before a retry is considered
  • partial-update endpoints preferred over overwriting ones

Incoming content is data, never instructions

Prompt-injection posture

An email, a contract exhibit or a carrier notice is treated as material to read, never as a command to obey. Because the model can only emit a label from a closed list, a crafted message has no verb available to it.

Under the hood
  • content boundaries enforced in the router, not in the prompt
  • no action key exists for "do what this message says"
  • adversarial fixtures run against the classifier
You stay in the loop

You keep the decisions
that are actually yours.

Approvals on the consequential things

Sensitive actions pause for a yes or no, with the evidence attached — from your phone, in a couple of minutes a day.

You author the rules

Approve the same call enough times and Doux offers to handle that one. You confirm once, explicitly. Everything outside those rules keeps coming to you.

A record you can hand to an auditor

Every action, its evidence, and the person who authorised it. When the E&O question comes, the answer is a record rather than a memory.

What actually restrains an agent.

Nobody can promise a language model will never be talked into something by a cleverly worded message. So we do not rely on the model behaving. It is fenced in by what it is structurally able to do: a closed list of actions, a deterministic layer that owns every destination, approval gates on anything irreversible, per-tenant isolation, and an audit record. If something does go wrong, it is contained, logged and visible.

Compliance status: pending SOC 2 Type I certification.

Inside your walls
from the first message.

Isolated, credential-safe and on the record from the day it is installed.

Runs in your environment Full data ownership Your credentials stay yours