← DCP5

Trust & security

What DCP5 actually does today — described plainly, including what hasn't happened yet rather than left unsaid.

Access control

Every company has its own Account Owner, Company Admins and Team Admins, each scoped to what they actually manage — a Team Admin for one team can't reach another team's data, and every privileged action (role changes, calendar changes, billing changes) is written to an audit log with the actor, action and outcome.

Tenant isolation

Every company's data — questions answered, calendars, billing, support messages — is scoped to that company. This has been directly tested: an administrator at one company was confirmed unable to manage or view another company's team, even while holding an otherwise broad role.

Account security

Passwords are hashed, never stored in plain text. Email addresses are verified before an account can sign in. Google and Microsoft sign-in are both supported alongside email/password.

Fairness in gamification

Response timing below a plausible-reading floor is flagged and excluded from speed bonuses and rankings. Leaderboards below a minimum participant count are hidden rather than shown short, so a small team is never exposed. Anyone can opt to appear anonymously to teammates on leaderboards.

Infrastructure

Hosted on Vercel with a managed Postgres database (Neon). Transactional email is sent via Resend. All traffic is served over HTTPS.

What hasn't happened yet

If any of this matters for your evaluation, ask — we'd rather tell you directly than have you assume.