Organisation isolation
Every protected query is scoped to the signed-in organisation and checked again against person-level access. A record identifier is never treated as permission.
Security
Domivio handles precise location and deeply personal evidence. Security is designed into identity, data access, storage, sync and audit—not added at the edge of the product.
Every protected query is scoped to the signed-in organisation and checked again against person-level access. A record identifier is never treated as permission.
Short-lived sessions, single-use sign-in links, device records, role permissions and revocation controls restrict access to the smallest necessary surface.
Document bytes remain in private object storage. Downloads are streamed only after organisation and person authorisation; folder names never determine access.
Manual travel corrections, rule changes, uploads and approvals create immutable events with actor, source, time and before/after context.
Native tracking is opt-in, visible and reversible. Offline events are encrypted on device and synchronised with stable identifiers to prevent duplicates.
TLS, encryption at rest, restrictive browser policies, private bindings, input validation, rate controls and structured redacted logs reduce single-point failure.
Clear boundary: these are the controls built into Domivio’s architecture. Domivio does not claim a certification until that certification has been independently completed and is current.
Organisations, households and people have stable relational identifiers. Membership and person-level access grants are separate records, allowing a family office to authorise one adviser for one household without exposing another. Automated tests attempt cross-organisation reads and writes and require them to fail closed.
Raw observations and interpreted journeys are deliberately separate. Coordinates are retained as factual inputs; country presence is a derived record with confidence and provenance. Aircraft-speed or high-altitude points default to air transit and do not become residency days. Uncertain movements remain uncertain until evidence or an authorised correction resolves them.
R2 stores encrypted-at-rest object bytes under opaque keys. D1 is the source of truth for person, country, date, type, journey link, verification state and retention. Upload credentials are short-lived and single-use. Download responses are private and non-cacheable.