BenKa.tech R&D LLC

Security & trust

A platform whose whole job is trust holds itself to the same bar.

DAVRO handles sensitive financial and carrier data on behalf of every customer. It's built so that isolation, encryption, and least-privilege aren't features bolted on — they're the architecture.

Per-tenant isolation

Row-level security enforces separation at the database, not in application code. One customer's data can never be reached from another's context — there is no shared pool and no co-mingling.

Encryption in transit & at rest

Traffic is served over TLS, and stored data is encrypted at rest. Sensitive material stays protected across its whole lifecycle.

Managed secrets

Credentials and keys live in a managed secrets store — never in plaintext, never written to logs. Response bodies that could carry financial data are kept out of logs by design.

Least-privilege access

Each connection operates only within its own tenant context, and every user sees only what their role permits. Access is scoped from the authenticated session, not inferred.

The assistant, contained by design

An advisor over your data — never a gatekeeper in front of it.

DAVRO's conversational assistant is deliberately caged. It reads; it doesn't act on its own authority. And the data boundary is never the model's judgment — it's enforced beneath it.

  • Session-derived scope. What a user can see comes from their authenticated session, not from anything they type.
  • Field-level projection. Sensitive fields are removed before an answer is ever formed.
  • Grounded answers. The assistant responds only from verified platform data, and says so.
boundary.tenantRLS · ENFORCED
boundary.subjectROW-SCOPED
boundary.fieldPROJECTED
assistant.writeNONE
source_of_truthPLATFORM DATA

Compliance posture

Where we are, stated plainly.

We'd rather tell you exactly where things stand than imply more. For vendor security reviews, we provide named sub-processors — including our accounting-connectivity provider — and complete your platform's security review as part of onboarding.

Status

SOC 2

SOC 2 Type I gap analysis complete; formal audit not yet initiated.

In place

Sub-processor list

Named sub-processors available for your vendor review on request.

Have a security questionnaire?

Send it over. We'll work through your vendor review and walk your team through the architecture in detail.