You own your data
Your raw data stays yours. What we may evaluate, what we may derive, how long we keep it, and what we may publish are spelled out in the contract, not assumed.
Trust and your data
You can evaluate what Dovrane recommends without handing over your systems, your authority, or ownership of your data.
Working beta · Testing against simulated storms · Operators always make the callWhat you get
Traceability, tenant separation, and the read-only boundary are how the product is built—not promises bolted on for a procurement review.
Integration with your OMS, ADMS, GIS, and work management is read-only: evidence comes in, a recommendation goes back out to your team. There is no write path and no control path from Dovrane into any operational system.
Where each piece of evidence came from, when it arrived, what was done to it, which model version saw it, and what your operator decided.
Every meaningful change keeps the previous version, its alternatives, and the reasoning behind it.
Public, licensed, utility-confidential, derived, and restricted evidence are tracked as separate classes, not pooled together.
Your evidence, everything derived from it, and all access, retention, and deletion are scoped to your workspace alone.
Data is protected in transit and at rest, access follows roles, and administrative actions leave an audit trail.
Monitoring, incident handling, recovery, and change-control procedures are defined for the beta service. They have not been exercised in a utility production environment.
We answer security questionnaires directly and will tell you what we have not done yet. We hold no certifications today and do not describe any we do not hold.
Your raw data stays yours. What we may evaluate, what we may derive, how long we keep it, and what we may publish are spelled out in the contract, not assumed.
Source, arrival time, what was done to it, which model version, which recommendation version, and who reviewed it stay linked together.
Evaluations run in a workspace isolated to you, with its own access, retention, and deletion controls.
Public, licensed, utility-confidential, derived, and restricted evidence are tracked as distinct classes.
When diligence starts
Dovrane holds no third-party security certification or attestation. There is no SOC 2 report, no ISO 27001 certificate, and no completed external penetration test, and we will not imply otherwise. We are a working beta with no utility deployments, so there is nothing audited to point you to yet. What your diligence team can have now is a walkthrough of the architecture, the read-only boundary, the tenant-isolation design, and the data-classification model, plus written answers to your security questionnaire. If a specific certification is a gate for you, tell us which one and we will give you our timeline rather than a maybe.
Security posture last reviewed 7 August 2026.
Next step
We answer directly, and we tell you what we have not done yet.