Skip to content

Security and data

What we can prove to you in five minutes — and nothing more

Security pages in this market all look alike: lists of badges and promises in the passive voice. Our rule on this page is one line: we do not write a claim we cannot show you working in a single session. And what we do not have is written here too.

Isolation is enforced by architecture, not by vigilance

Separating one organisation from another is not a condition written into one query and forgotten in the next. It is a series of layers that begins with initialising tenant context before any read and ends with automated tests that fail the build if a single row leaks from one organisation to another.

The premise underneath it is that failure must be loud and closed: a query running without tenant context does not return everyone's data — it aborts. A tool that silently returns the wrong rows is more dangerous than one that stops.

  • A dedicated system user

    Diwan has its own system user, its own process pool and a confined file path, so it cannot read the files of neighbouring applications on the same server.

  • A database only it can reach

    An account scoped to Diwan's database alone, not a shared account that can reach other applications' databases.

  • Proven by probe, not by assertion

    We tested the isolation with a probe that tries to read what it must not — server secrets and neighbours' files — and all of it is blocked.

Transport and backups

Every connection to Diwan is encrypted, and backups are daily and encrypted with a key whose secret half is not on the server — so whoever seizes the server cannot open its backups.

And more important than having a backup is having tried it: we ran a real restore drill from an encrypted backup until the tables came back with matching row counts. A backup never restored is not a backup but an assumption.

  • A three-way backup guard

    It catches outright failure, false success with a suspiciously small archive, and total silence — the most dangerous of the three, because silence looks like health.

  • Every uploaded file is scanned

    Files pass through quarantine and a scan before the Knowledge Center, and whatever fails does not exist in the place it would be read from.

  • An audit log verified daily

    A log that reveals tampering but is never questioned is not a log — so its integrity is verified automatically every day with an exit code.

Where your data lives — and the sovereign option

Our servers are in Frankfurt, Germany today, and we say so before signing rather than after. For anyone who requires a specific location — a government body or an organisation bound by regulation — we provide a dedicated install on a server in that location under a contractual arrangement, not a toggle in the interface.

And a full export in open formats is included on every plan. Leaving Diwan has to be as easy as joining it; otherwise staying is captivity rather than choice.

And what we do not have today

We hold no ISO certificate and no SOC 2 report, and we will not write anything that implies otherwise. We did run a full internal security review and fixed every blocking item we found — but it was carried out by the same party that built the system, so it cannot be cited to an enterprise buyer, and we say that before the buyer does.

An independent third-party review is scheduled by written decision, and we will publish its outcome when it is done. Until then, everything on this page is built and inspectable, and anything not on it does not exist.

Questions about security

Can your staff see our data?

Nobody here opens your organisation's data except through a support session that you request and approve, which expires, and which is logged with who opened it and why. The identity of whoever entered is shown to you prominently, not hidden.

Is our data encrypted?

Transport is encrypted, and backups are encrypted with a key whose secret half is not on the server. Per-organisation encryption keys are not built today and we do not claim them.

What happens to our data if we end the subscription?

You export all of it in open formats, included on every plan. Your data is not deleted the moment the subscription ends — it remains for a stated period during which you can retrieve it.

Can you install Diwan on our own server?

Yes, for organisations that require it, under a contractual arrangement priced case by case. It is a clause in the contract, not a button in the interface.

Ask for proof, not for promises

We will show you every claim on this page working in a single session, and answer your security officer's questions directly.

Start free