Documentation

Other

Security and data

Updated 05/10/2026

Signing in

No passwords — a one-time code sent to your email (6 digits, valid for 5 minutes, limited number of attempts). There is no password that can leak, or that matches the password you use on other websites.

Our recommendation: since access to the programme is tied to your email account, turn on two-factor authentication (2FA) on the email account itself (Gmail, Outlook and the others offer it free of charge). That gives signing in to duplo additional protection too.

Data isolation

Every company sees only its own data — customers, documents, items. Every database query is tied to your organisation.

SEF and SEO API keys — encrypted and invisible

Your API keys for SEF (the national e-invoicing system) and e-delivery notes (SEO) are stored in the database encrypted (AES-256), and after entry they are never shown anywhere in the programme again — you only see that they are saved. You can replace a key with a new one or remove it; nobody can read it, neither through the programme nor by looking into the database. If you misplace it, you can issue a new key on the SEF portal at any time.

Where the data is and what the programme runs on

The database and files are in the European Union (Frankfurt). PDF documents are served through the application after an access permission check — there are no public links.

The infrastructure duplo runs on has its own security certificates (SOC 2) and public security pages, so you can verify the claims directly with the providers:

For real-time notifications in the support chat we use Pusher (EU cluster, Ireland). Neither the content of messages nor company data passes through it — only a signal that a new message has arrived, and the application reads the content from our database after checking that you are signed in.

The snapshot principle

An issued document permanently keeps the details of the issuer and the customer as they were at the moment of issue — later changes to the lists do not alter history. In addition, the document history records who did what and when.

Legal framework: we process personal data in accordance with the Serbian Personal Data Protection Act (ZZPL) and the GDPR — the data processing agreement is an integral part of the terms of use. Details: Terms of use, Privacy policy and GDPR.