Security
The controls DOG-E currently uses—and the limits you should understand before uploading a document.
Effective and last updated: July 29, 2026
Account and access controls
- Google verifies sign-in tokens; DOG-E does not receive your Google password.
- Uploads require an existing, verified DOG-E account.
- Job status and downloads require the owning account or a short-lived, unguessable job capability used for live progress.
- Administrative access is restricted to explicitly allowlisted identities.
Document lifecycle
- Each upload is processed in an isolated job directory and deleted after the retention period shown in the product, currently two hours.
- You can delete a completed result or your entire account sooner.
- Downloads use authenticated requests and private, no-store cache directives.
Transport and browser protections
Production traffic is intended to use HTTPS. The web deployment sets content-type, referrer, framing, permissions, and transport-security headers. Cloudflare Turnstile helps detect automated abuse before a document is accepted.
Third parties and limitations
Google, Cloudflare, infrastructure providers, and the document-processing provider form part of the security boundary. See Subprocessors. No internet service is risk-free, and DOG-E does not claim end-to-end encryption: document processing necessarily requires service components to access file content.
Report a vulnerability
Email support@dog-e.app with the affected URL, a clear reproduction, and potential impact. Do not access other users’ data, degrade the service, use destructive testing, or publicly disclose an unresolved issue. We will acknowledge good-faith reports as soon as practical.