trust center
Security
Divelai asks you to route sensitive data through it. That is a large request, and it deserves specifics rather than badges. So: we are in closed beta, we hold no third-party certifications, and this page describes how the system is built rather than which logos we have earned. Anything not yet true is marked as outstanding rather than quietly omitted.
Where data is processed and stored
Payloads
Request and response bodies are processed in memory and are not written to disk. Divelai does not retain payload content after a request completes. Self-hosted deployments never send payloads outside your infrastructure at all.
The token vault
Token-to-value mappings are the only sensitive data Divelai stores. The vault is encrypted with per-tenant keys, isolated from the processing path, and pinned to a region you choose. On the self-hosted plan it runs in your own database and Divelai has no access to it.
Audit records
Logs hold detector, transform, token, policy version, destination, and a keyed hash of the original value. Original values are never written to logs. Retention window [CONFIRM]
Encryption
TLS 1.3 in transit with HSTS preload. AES-256 at rest. Key management and rotation schedule [CONFIRM KMS provider and rotation period]
Tenant isolation
Isolation model — logical or dedicated, and at which layer [CONFIRM]
Access control
Internal access to production, break-glass procedure, and whether any Divelai employee can read a customer vault [CONFIRM]
Certifications: we hold none
Divelai is in closed beta and holds no third-party security certifications. Not SOC 2, not ISO 27001, and no published penetration test. We are not going to tell you an audit is "in progress" as a way of implying it is nearly finished, and there are no badges on this site.
This page will say otherwise the day it is true, and the evidence will be available for you to check rather than described in a marketing sentence.
What that means for your review
If your procurement process requires a current SOC 2 Type II report or an ISO 27001 certificate before signing, Divelai cannot meet that requirement today. Tell us early rather than late — we would rather be ruled out in the first conversation than in the last one.
What we can do in the meantime: answer your security questionnaire in full, walk your team through the architecture, describe our data handling in writing, and sign a DPA. Several teams have run a bounded beta on that basis. Whether it is enough is your call to make, not ours to talk you into.
What we will publish, and when
In roughly this order. No dates, because a date we miss is worse than no date at all.
| Item | Status today | What you will get |
|---|---|---|
| Security questionnaire responses | Available now | Completed on request during a review, under NDA if you prefer |
| Architecture documentation | Available now | Written data-flow and data-handling description, plus a call with an engineer |
| Signed DPA | Available now | Pre-signed, with subprocessors listed |
| Independent penetration test | Not yet commissioned | Public summary letter; full report under NDA |
| SOC 2 Type II | Not started | Report under NDA, once an observation period has actually been completed |
| ISO 27001 | Not started | Certificate and statement of applicability |
| Public status page | Not yet published | Uptime and incident history |
| Subprocessor list | Published | Current list |
Reporting a vulnerability
Report findings through the contact form, choosing Security review. Include enough detail to reproduce. We acknowledge within one business day and will keep you updated until the issue is closed.
Test only against accounts and data you own. We will not pursue legal action against researchers who act in good faith, stay within their own tenant, avoid degrading service for others, and give us reasonable time to fix an issue before disclosing it.
Machine-readable contact details are at /.well-known/security.txt. Bug bounty programme [CONFIRM]
If something goes wrong
Incident notification commitments, including the window in which affected customers are contacted and what the notification contains [CONFIRM]
Business continuity, backup, and restore targets [CONFIRM RPO / RTO]
Our own supply chain: dependency scanning, signed builds, and SBOM availability [CONFIRM]
Security review questions welcome.
Send your questionnaire. We would rather answer it early than at the end of a procurement cycle.