Infrastructure & Data Security Policy
How Diligio hosts customer data and the technical and organisational controls that protect it: encryption, tenant isolation, access control, monitoring, and responsible disclosure.
Last updated 11 June 2026
1. Data Isolation & Tenancy
Customer documents and knowledge-base content are isolated per organisation using PostgreSQL Row-Level Security (RLS) at the database engine level. Every query is constrained to the caller's organisation, so one tenant cannot read another tenant's data.
2. Infrastructure Hosting
The platform is hosted entirely on Amazon Web Services (AWS) within EU data centres (Paris, eu-west-3) and delivered globally via the AWS CloudFront CDN. Core database persistence and file storage are provisioned on AWS Amazon S3 and managed Supabase (PostgreSQL) infrastructure across Tier-III cloud facilities. A complete list of infrastructure and processing providers is published on our Sub-processors page.
3. Redundancy & Recovery
Data is backed up automatically on our AWS and Supabase infrastructure, with disaster-recovery procedures in place to restore service and data after an incident.
4. Encryption & Cryptographic Controls
Data at Rest: All proprietary records and database volumes are secured using AES-256 bit encryption profiles across our AWS and Supabase infrastructure.
Data in Transit: All data transmission, API payloads, and edge routing telemetry are strictly encrypted in transit utilising TLS 1.2+ over HTTPS protocols.
5. Access Control & Authentication
Platform access is governed by strict authentication protocols. Tenant workspaces utilise role-based access control (RBAC) to ensure that users can only access resources explicitly authorised for their operational tier.
6. LLM & AI Model Data Boundaries
Customer documents and text are sent to our AI providers only to draft and verify answers at request time, under paid API terms. Your content is strictly confidential and is never used to train foundational models.
7. Vulnerability Management & Responsible Disclosure
Our dependencies and application code are scanned automatically for known vulnerabilities, and we patch the issues we find promptly.
Responsible Disclosure: We highly value the security research community. While we do not currently operate a paid bug bounty program, we welcome responsible disclosure from white-hat researchers and will publicly acknowledge individuals who report serious, verifiable vulnerabilities. Please direct all security reports to security@diligio.co.
8. Compliance Validation Target
SOC 2 Type II and ISO/IEC 27001 Certification Compliance Frameworks are planned. We are actively building toward formal third-party attestation of our security controls.