ADirectorOS

DirectorOS Security and Data Handling Notice

Effective date: June 13, 2026

This notice summarizes DirectorOS security and data handling practices for customers, prospects, administrators, and auditors. It is not a replacement for a signed security addendum, data processing agreement, business associate agreement, or legal review where one is required.

1. Security Program Direction

DirectorOS is being developed toward a SOC 2-style operating model. Current readiness tooling includes security posture checks, policy management, access reviews, evidence storage, incident/drill logs, vendor reviews, privacy request tracking, and exportable compliance packets.

2. Data Security Principles

DirectorOS follows practical data protection principles:

  • Know what data is stored and where it lives.
  • Limit collection to data needed for authorized operations.
  • Protect retained data with access, encryption, audit, and session controls.
  • Retain records according to customer, legal, and operational needs.
  • Plan ahead for incidents, backups, recovery, and customer communication.

These principles align with broadly accepted business guidance for protecting personal information and preparing incident response procedures.

3. Access Control

DirectorOS supports:

  • Role-based workspace visibility.
  • Separate admin rights.
  • Owner console access for owner users.
  • User status controls.
  • Session revocation.
  • Passkey/MFA support.
  • Quarterly-style access review workflows.
  • Audit evidence for access review decisions.

Customer administrators are responsible for assigning roles carefully and removing access when personnel no longer need it.

4. Authentication and Sessions

DirectorOS supports password login, passkeys, secure session handling, idle timeout settings, absolute session age settings, session revocation, and failed login logging.

Production deployments should configure a production session secret, production encryption key, secure cookies, HTTPS, and appropriate environment variables.

5. Encryption and File Handling

DirectorOS supports encrypted file handling for uploads and backups where configured. Production deployments should store encryption keys in environment secrets and avoid committing secrets to source control.

Users should not upload unnecessary sensitive information. Files should be retained only as long as needed for authorized business, legal, or operational purposes.

6. Audit Logs

DirectorOS maintains audit and operational event logs for important actions, including login events, security events, case operations, custody events, administrative changes, and compliance records.

Certain records, such as custody ledger events and security audit events, may be retained to preserve operational integrity and evidence history.

7. Custody Ledger

DirectorOS custody workflows are designed to support chain-of-custody integrity through QR codes, transfer events, audit checks, location tracking, personal effects manifests, delivery checklists, and tamper-evident ledger concepts.

Users should scan or log custody events at each physical handoff, arrival, release, audit check, or effects transfer.

8. Backups and Recovery

DirectorOS includes backup and backup-test tools. Customer organizations should define backup frequency, restore testing, recovery objectives, and evidence collection procedures appropriate for their operations.

9. Incident Response

DirectorOS includes incident and drill registers for recording availability, security, privacy, tabletop, and operational events. Incident records should include detection time, severity, customer impact, containment steps, corrective actions, owner, and post-incident review status.

10. Vendor and Integration Review

DirectorOS may rely on hosting, AI, communication, calendar, purchasing, task, and case management integrations. Customer organizations should review vendor agreements, data access, SOC reports or security materials, API credentials, and renewal dates.

11. Privacy Requests and Retention

DirectorOS includes a privacy request register for retention questions, deletion requests, access requests, correction requests, and privacy questions.

Requests should be verified, assigned to an owner, documented, completed when appropriate, and retained as evidence.

12. Customer Responsibilities

Customer organizations are responsible for:

  • Determining which laws and contracts apply.
  • Configuring roles and admin rights.
  • Training users.
  • Reviewing AI outputs.
  • Maintaining third-party agreements and API credentials.
  • Managing data retention and deletion decisions.
  • Preserving required custody and audit records.
  • Reporting security or privacy concerns promptly.

13. Contact

Security questions may be directed to:

security@directoros.io