Security & infrastructure

Secure architecture
& governance

Diligio protects highly sensitive proposals, asset registries, and corporate knowledge. These are the controls in place today, and the certifications we are working towards.

  • Never trains AI models
  • Role-based access control
  • Hardened document handling
  • You own your data
Controls

Defence in depth, layer by layer

The technical safeguards defending your environment right now, in the order a request or a file meets them.

Edge
Abuse and rate limiting
rate-limited per client
Identity
Enterprise single sign-on
SAML 2.0 / OIDC · SCIM 2.0
Upload
Malware scanning on every upload
hardened, version-pinned parsers
Tenant
Per-tenant data isolation
PostgreSQL row-level security
Record
Append-only audit logging
tamper-evident trail
HostingAWS, EU (Paris · eu-west-3)
Global deliveryAmazon CloudFront
EncryptionAES-256 at restTLS 1.2+ in transit
ResilienceAutomated backupsDR procedures

Data protection

Your content stays yours, encrypted at rest and in transit, and walled off from every other tenant.

Your data never trains AI models

Your content is strictly confidential. Documents and text are sent to our AI providers, Anthropic and Google, only to draft and verify answers at request time, under paid commercial API terms, and are never used to train foundational models.

Advanced cryptographic standards

All records, parsed assets and files are encrypted at rest with AES-256. Data in transit between your browser and our endpoints is encrypted with TLS 1.2 or higher.

Per-tenant data isolation

Each organisation's data is isolated at the database layer using PostgreSQL Row-Level Security, so users can only access data belonging to their own organisation.

Identity & access

Authenticate through your own identity provider, and govern exactly who can do what.

Enterprise single sign-on

Connect your identity provider over SAML 2.0 or OIDC. Staff are provisioned just-in-time into your workspace on first login, scoped to your DNS-verified domain, and SSO can be enforced so they authenticate only through your IdP.

Automated user provisioning (SCIM)

Connect SCIM 2.0 to provision and, just as importantly, deprovision accounts automatically as your directory changes, so people who leave your organisation lose access without any manual step.

Role-based access control

Granular roles govern who can read, edit, and approve. Any AI agent you connect inherits the permissions of the person who created it and can never exceed them, re-checked live on every request.

Threat defence

Hostile traffic and malicious files are stopped before they ever reach your data.

Abuse and rate limiting

Public and authenticated endpoints are rate-limited per client, stopping volumetric abuse and billing-exhaustion attempts before they reach your data.

Malware scanning on every upload

Every file you upload is scanned for malware before it is ingested, so an infected document is rejected at the door rather than stored or processed.

Hardened document handling

Uploaded files are parsed with hardened, version-pinned parsers and in-document scripting disabled, so a malicious file cannot execute code during ingestion.

Accountability & ownership

A tamper-evident record of every sensitive action, and your data returned on request.

Append-only audit logging

Sensitive actions are recorded to an append-only audit log, so there is a tamper-evident trail of who did what and when across your workspace.

You own your data

Your content is yours. On termination we return or delete all of it at your choice, as set out in our Data Processing Agreement.

Certifications & documentation

What we can share in a review

The certifications we are working towards, and the paperwork we can share during a security review.

SOC 2 Type II report

Planned

Comprehensive audit mapping across the security, availability, and confidentiality trust service criteria.

Mapped to the security, availability, and confidentiality criteria. External audit planned.

ISO/IEC 27001 certification

Planned

The international standard for information security management, validating how we identify, treat, and review security risk.

Aligned to the Annex A controls. External certification planned.