Security
Dike is engineered from the ground up for sovereign legal intelligence. We enforce zero customer data retention for model training, mandatory transport encryption, and deterministic citation verification.
Zero Retention for Foundation Model Training
Your search queries, document embeddings, and context payloads are strictly isolated. We process requests in ephemeral memory buffers and never use customer data to train, fine-tune, or adapt foundation models.
End-to-End Transport Encryption (TLS 1.3)
All REST and gRPC traffic enforces TLS 1.3 with modern elliptic curve cipher suites (ECDHE-ECDSA-AES256-GCM-SHA384) and Perfect Forward Secrecy. Legacy protocols are blocked at the edge.
Phishing-Resistant FIDO2 Authentication
Developer portal sign-ins support hardware-backed WebAuthn passkeys (Touch ID, Face ID, YubiKey). API secret keys are stored as salted SHA-256 hashes and cannot be recovered in plaintext.
Deterministic Grounding & Hallucination Filter
Every citation emitted by the legal reasoning engine is deterministically verified against retrieved official gazette text. Unverified citations are automatically stripped before response egress.
Strict Multi-Tenant & Vector Isolation
Logical and physical boundaries enforce complete tenant segmentation across vector search indexing, context window buffers, and gRPC execution pools.
Coordinated Vulnerability Disclosure
We welcome responsible security research. If you discover a vulnerability, contact our security team for responsive triage under our safe harbor policy.