Security
& Trust
Diapason AI is built with security and privacy at its core. We process all data within the European Union and work exclusively with SOC 2 certified infrastructure providers.
of AI users bring their own AI tools to work — pasting sensitive team data into consumer apps with zero oversight.
Your team deserves a safe AI.
Security Practices
Enterprise-grade security controls built into every layer of our infrastructure.
Least Privilege
Database functions default to no permissions. Each operation explicitly granted only required access.
Tenant Isolation
Complete data isolation between organizations using PostgreSQL Row-Level Security. Each customer's data is logically separated at the database level.
Encryption
AES-256 at rest, TLS 1.2+ in transit. All connections encrypted end-to-end.
Passwordless Auth
Magic link, Google OAuth, or Microsoft OAuth. No passwords stored, no credentials to leak.
Environment Isolation
Development, staging, and production fully separated. No data sharing between environments.
DDoS & WAF Protection
Cloudflare Web Application Firewall protects against attacks. Rate limiting and bot protection included.
EU Data Residency
All your data is processed and stored within the European Union.
All infrastructure is configured to process and store data exclusively within the European Union. No data leaves the EU.
Security (WAF)
Cloudflare
EU Edge
Hosting
Vercel
Paris, France
Database & Auth
Supabase
Paris, France
AI
Vertex AI
EU (BE, FR, NL, DE)
Analytics
PostHog
EU Region
Subprocessors
We work exclusively with trusted, certified infrastructure providers.
| Processor | Purpose | Location | Certifications |
|---|---|---|---|
| Cloudflare | WAF & DDoS Protection | Global (EU routing) | SOC 2ISO 27001PCI-DSSDPA ✓ |
| Supabase | Database & Auth | EU (Paris) | SOC 2HIPAADPA ✓ |
| Vercel | Hosting & Edge Functions | EU (Paris) | SOC 2ISO 27001DPA ✓ |
| Google Vertex AI | AI Conversations & Embeddings | EU (BE, FR, NL, DE) | SOC 2ISO 27001DPA ✓ |
| PostHog | Product Analytics | EU | SOC 2HIPAADPA ✓ |
| Sentry | Error Monitoring | EU (Germany) | SOC 2ISO 27001HIPAADPA ✓ |
| Stripe | Payments | EU (Ireland) | SOC 2PCI-DSSDPA ✓ |
| AssemblyAI | Transcription | EU (Dublin) | SOC 2PCI-DSSDPA ✓ |
| Resend | EU (Ireland) | SOC 2DPA ✓ |
Documents & Resources
Report a Security Issue
We value responsible disclosure. If you've discovered a vulnerability, please contact us.
We commit to:
- •Acknowledging reports within 48 hours
- •Keeping you informed of our progress
- •Not pursuing legal action for good-faith reports
Ready to get started?
You've read the details. Your team's privacy is safe with us.