Security Governance
Dilmach applies security principles across the design, development and operation of the Services. Security responsibilities are assigned to accountable personnel within the organisation, who can be reached at the security contact below.
Infrastructure
Dilmach uses Vercel for application hosting and deployment infrastructure and Neon for database infrastructure. Independent provider certifications and attestations apply to the respective provider and within the scope defined by that provider. They do not constitute certification of Dilmach.
Vercel
Application hosting, deployment infrastructure and file storage (Vercel Blob)
Provider-level assurance
Neon
Primary database infrastructure (all application and Customer Content data)
Provider-level assurance
Encryption
Data in transit to and from the Services is encrypted using industry-standard protocols (TLS). Encryption of data at rest relies on the platform-level capabilities of our infrastructure providers, Vercel and Neon, as described in their respective security documentation linked above.
Access Control
Access to production systems and Customer Content is restricted to authorised personnel based on the principle of least privilege. Within the Services, role-based permissions (for example, owner, admin and member roles) govern which Authorised Users of a Customer's workspace can access, modify or administer particular functionality and data.
Authentication
Account access to the Services is protected by authentication controls, including email-based identity verification and an optional PIN-code verification step as an additional factor for account sign-in. Passwords and PIN codes are stored using industry-standard cryptographic hashing rather than in plain text.
Monitoring
Dilmach monitors relevant systems for security events, including through logging and alerting capabilities provided by our infrastructure providers. We do not publicly disclose the full detail of our internal monitoring configuration, as doing so could itself create a security risk.
Vulnerability Management
Dilmach evaluates and addresses known vulnerabilities affecting the Services, including dependency and platform updates. Enterprise customers may request additional information about our vulnerability management practices, including any penetration testing, by contacting the security contact below and entering into an appropriate confidentiality arrangement.
Incident Response
Dilmach maintains processes for detecting, assessing, responding to and documenting security and personal data incidents. Where Dilmach acts as processor, Dilmach will notify the relevant customer without undue delay after becoming aware of a personal data breach affecting Customer Personal Data, subject to applicable law and the applicable Data Processing Agreement.
Backups and Resilience
Backup frequency, retention and disaster-recovery practices depend on our infrastructure providers' capabilities, in particular Neon's database backup and point-in-time recovery features, and Dilmach's configuration of them. Backups are not a substitute for Customer-side export of Customer Content that the Customer wishes to independently retain.
Secure Development
Changes to the Services follow a development process intended to reduce the risk of introducing security issues, including version-controlled source code and a staged deployment pipeline (preview deployments prior to production) provided by our hosting infrastructure.
Third-Party Risk
Dilmach evaluates infrastructure providers, including Vercel and Neon, before relying on them and monitors their published security and compliance information. See our Subprocessors page for details.
Privacy Governance
Dilmach is developing its privacy management practices with reference to GDPR accountability principles and recognised privacy information management practices. Dilmach does not claim ISO/IEC 27701 certification unless and until it has actually obtained such certification.
Customer Responsibilities
Security is a shared responsibility. Dilmach is responsible for the security and privacy controls applicable to its own Services and processing activities. Infrastructure providers are responsible for the security of their respective services within their contractual and technical scope. Customers are responsible for how they configure and use Dilmach and for the lawfulness of personal data they submit to the Services.