Doux
Security

Your research happens
inside your own walls.

Doing the looking means going into the systems that hold your book — the management system, the mailbox, the carrier portals. So the whole question is where that walking happens, and who can see it. The answer is: in your own isolated instance, against your own credentials, which never leave your environment. Nothing about your book is pooled with another agency's, and every step is written down.

The model never executes anything itself. It proposes; a deterministic layer decides and acts. You get the capability without having to become a security engineer.

Isolated per tenant · your credentials never leave your environment · every action on the record

Straight talk

What we will not tell you.

Plenty of vendors open a security page with an attack they survived. We are early, and we are not going to dress up numbers we have not earned. Here is what we can actually stand behind — the architecture, not a scoreboard.

Credentials never leave your environmentCarrier, portal and mailbox credentials stay in your tenant. We hold no copy.
Per-tenant key separationOne agency's secrets are not reachable from another's instance, by construction.
The model never executesIt proposes an action from a closed list. A deterministic layer decides and acts.
Irreversible actions need a personAnything that leaves the agency or cannot be undone waits for a named human approval.
Claude vs Doux

Built on Claude.
Hardened for an agency.

Claude is the foundation Doux runs on, and you can absolutely run it yourself. Doing so hands you full control — and with it, full responsibility for the isolation, the guardrails and the audit trail. Doux ships that same foundation already fitted to a commercial P&C agency, with the boundaries built in.

Comparison of running Claude yourself against running Doux
 Claude, self-hostedDoux
Your data stays in your environmentYesYes
You control what the agents can reachYesYes
Knows commercial P&C — forms, endorsements, x-datesYou build itBuilt in
Drives your management system and carrier portalsYou build itBuilt in
Deterministic action layer — the model cannot executeYou build itBuilt in
Approval queue for irreversible actionsYou build itBuilt in
Append-only audit record of every actionYou build itBuilt in
Per-tenant isolation and key separationYou build itBuilt in
Writes read back and verified after every changeYou build itBuilt in
Fitted to your agency's own rulesYou build itBuilt with you

Every row above describes Doux as it is built today. Where something is still in progress we say so on this page rather than in a tick box.

Defence in depth

Every layer, on purpose.

Security is not one wall. Each card below has the plain-English version on top and what it actually means underneath.

Your credentials stay yours

Tenant-held secrets

The logins for your management system, your carrier portals and your mailbox live in your own tenant environment. We do not hold a copy, and no other tenant's instance can reach them.

Under the hood
  • per-tenant secret store, separate keys
  • no shared credential pool across tenants
  • secrets stripped from logs and API responses

The model proposes, it never executes

Deterministic action layer

The language model emits a label from a closed list of permitted actions. It never writes a command, never names a recipient, and never touches your systems directly. A deterministic router decides what actually happens.

Under the hood
  • closed enum of action keys, not free text
  • the router owns every address and destination
  • an unrecognised label fails closed

Irreversible actions wait for a person

Approval gate

Anything that leaves the agency, changes coverage, or cannot be undone stops and asks a named human. Approval is checked against a roster — not against a field that merely contains a name.

Under the hood
  • approver checked against an allow-list, failing closed
  • approval recorded with who, what and the evidence shown
  • rules you author yourself decide what is routine

Every action is on the record

Append-only audit

What was done, by which agent, on what evidence, and who approved it. Entries are appended and chained — an earlier entry cannot be quietly rewritten later.

Under the hood
  • hash-chained entries, append-only
  • actor, action, target, outcome on every state change
  • queryable for an audit or an E&O question

Writes are read back

Verify-after-write

Management systems can commit a record and then fail while answering. Doux never treats an error as a failed write — it reads the record back and confirms the real end state before reporting anything as done.

Under the hood
  • no blind retry on an ambiguous response
  • state re-read before a retry is considered
  • partial-update endpoints preferred over overwriting ones

Incoming content is data, never instructions

Prompt-injection posture

An email, a contract exhibit or a carrier notice is treated as material to read, never as a command to obey. Because the model can only emit a label from a closed list, a crafted message has no verb available to it.

Under the hood
  • content boundaries enforced in the router, not in the prompt
  • no action key exists for "do what this message says"
  • adversarial fixtures run against the classifier
You stay in the loop

You keep the decisions
that are actually yours.

Approvals on the consequential things

Sensitive actions pause for a yes or no, with the evidence attached — from your phone, in a couple of minutes a day.

You author the rules

Approve the same call enough times and Doux offers to handle that one. You confirm once, explicitly. Everything outside those rules keeps coming to you.

A record you can hand to an auditor

Every action, its evidence, and the person who authorised it. When the E&O question comes, the answer is a record rather than a memory.

Straight talk on what actually restrains an agent.

Nobody can promise a language model will never be talked into something by a cleverly worded message. So we do not rely on the model behaving. It is fenced in by what it is structurally able to do: a closed list of actions, a deterministic layer that owns every destination, approval gates on anything irreversible, per-tenant isolation, and an audit record. If something does go wrong, it is contained, logged and visible.

And the honest status line: a formal security programme is in progress. We do not hold SOC 2 and we do not claim it. Ask us where it stands and we will tell you exactly, in writing.

Inside your walls
from the first message.

Isolated, credential-safe and on the record from the day it is installed.

Runs in your environment Full data ownership Your credentials stay yours