Trust

Security at Dilmach

Security and privacy are fundamental to how we design, operate and improve Dilmach.

Effective date:
23 September 2026
Last updated:
23 September 2026
Version:
1.0

Security Governance

Dilmach applies security principles across the design, development and operation of the Services. Security responsibilities are assigned to accountable personnel within the organisation, who can be reached at the security contact below.

Infrastructure

Dilmach uses Vercel for application hosting and deployment infrastructure and Neon for database infrastructure. Independent provider certifications and attestations apply to the respective provider and within the scope defined by that provider. They do not constitute certification of Dilmach.

Vercel

Application hosting, deployment infrastructure and file storage (Vercel Blob)

Provider-level assurance

SOC 2 Type IIISO 27001:2022EU-U.S. Data Privacy Framework

Neon

Primary database infrastructure (all application and Customer Content data)

Provider-level assurance

SOC 2 Type IIISO/IEC 27001:2022ISO/IEC 27701:2019

Encryption

Data in transit to and from the Services is encrypted using industry-standard protocols (TLS). Encryption of data at rest relies on the platform-level capabilities of our infrastructure providers, Vercel and Neon, as described in their respective security documentation linked above.

Access Control

Access to production systems and Customer Content is restricted to authorised personnel based on the principle of least privilege. Within the Services, role-based permissions (for example, owner, admin and member roles) govern which Authorised Users of a Customer's workspace can access, modify or administer particular functionality and data.

Authentication

Account access to the Services is protected by authentication controls, including email-based identity verification and an optional PIN-code verification step as an additional factor for account sign-in. Passwords and PIN codes are stored using industry-standard cryptographic hashing rather than in plain text.

Monitoring

Dilmach monitors relevant systems for security events, including through logging and alerting capabilities provided by our infrastructure providers. We do not publicly disclose the full detail of our internal monitoring configuration, as doing so could itself create a security risk.

Vulnerability Management

Dilmach evaluates and addresses known vulnerabilities affecting the Services, including dependency and platform updates. Enterprise customers may request additional information about our vulnerability management practices, including any penetration testing, by contacting the security contact below and entering into an appropriate confidentiality arrangement.

Incident Response

Dilmach maintains processes for detecting, assessing, responding to and documenting security and personal data incidents. Where Dilmach acts as processor, Dilmach will notify the relevant customer without undue delay after becoming aware of a personal data breach affecting Customer Personal Data, subject to applicable law and the applicable Data Processing Agreement.

Backups and Resilience

Backup frequency, retention and disaster-recovery practices depend on our infrastructure providers' capabilities, in particular Neon's database backup and point-in-time recovery features, and Dilmach's configuration of them. Backups are not a substitute for Customer-side export of Customer Content that the Customer wishes to independently retain.

Secure Development

Changes to the Services follow a development process intended to reduce the risk of introducing security issues, including version-controlled source code and a staged deployment pipeline (preview deployments prior to production) provided by our hosting infrastructure.

Third-Party Risk

Dilmach evaluates infrastructure providers, including Vercel and Neon, before relying on them and monitors their published security and compliance information. See our Subprocessors page for details.

Privacy Governance

Dilmach is developing its privacy management practices with reference to GDPR accountability principles and recognised privacy information management practices. Dilmach does not claim ISO/IEC 27701 certification unless and until it has actually obtained such certification.

Customer Responsibilities

Security is a shared responsibility. Dilmach is responsible for the security and privacy controls applicable to its own Services and processing activities. Infrastructure providers are responsible for the security of their respective services within their contractual and technical scope. Customers are responsible for how they configure and use Dilmach and for the lawfulness of personal data they submit to the Services.

Security Contact

To report a security issue or request additional security information, contact legal@dilmach.com.