Dike
ALL SECURITY & GROUNDING CONTROLS OPERATIONAL
TLS 1.3 Zero Training 100% Grounded
Dike Trust Center Artwork

Enterprise Security, Privacy & Compliance Matrix

Explore Dike's real-time security posture: zero-retention AI governance, hardware-backed WebAuthn passkeys, and verified statutory compliance across Saudi Arabia, the UAE, and Egypt.

AI Training0% RetainedZero customer storage
TransportTLS 1.3 & gRPCPerfect forward secrecy
Hallucination100% GroundedGazette verified filter
Regional CoverageKSA • UAE • EGPDPL / ECC compliant
VERIFIED CONTROL MATRIX

Searchable Security & Governance Controls

DATA-01

Zero Customer Data Retention for Foundation Model Training

AI & Data Governance

Enterprise queries, prompts, document embeddings, and context payloads are strictly isolated. We never use customer data to train, fine-tune, or adapt foundation models.

Enforced

Enterprise queries, prompts, document embeddings, and context payloads are strictly isolated. We never use customer data to train, fine-tune, or adapt foundation models.

Technical Implementation Specifications
Stateless execution environments: Request memory buffers are ephemerally created per gRPC/REST call and purged upon stream termination.
Customer data is never exported to training queues, vector training caches, or feedback datasets.
Strict data isolation between customer tenant IDs, API keys, and organizational boundaries.
Verification Artifact / Payload
DATA-01 / Verification
# Verified Header: No Customer Retention Policy
# Header X-Dike-Zero-Retention: active is returned on every reasoning request
curl -I -X POST https://api.dike.it.com/v1/reason \
  -H "Authorization: Bearer $DIKE_API_KEY" \
  -H "Content-Type: application/json" \
  -d '{"question":"مسؤولية الناقل الجوي"}'
Statutory / Regulatory MappingKSA PDPL Art. 5 (Purpose Limitation) • UAE Law 45/2021 Art. 4 • GDPR Art. 5(1)(b)
Verification MethodContinuous Automated CI/CD Data Boundary Scans
SEC-TLS

End-to-End Transport Encryption (TLS 1.3 & gRPC mTLS)

Cryptography & Ingress

All traffic across public and private endpoints enforces TLS 1.3 with modern elliptic curve cipher suites (ECDHE-ECDSA-AES256-GCM-SHA384) and Perfect Forward Secrecy.

Verified Active
AUTH-PASSKEY

FIDO2 WebAuthn Hardware Passkeys & Salted Hashed Keys

Cryptography & Ingress

Developer portal sign-ins support phishing-resistant WebAuthn passkeys (Touch ID, Face ID, YubiKey). API secret keys are stored as salted SHA-256 hashes.

Verified Active
GUARD-01

100% Grounded Deterministic Verification Filter

Statutory Hallucination Guard

Every citation emitted by the legal reasoning engine is deterministically verified against retrieved gazette texts. Unverified citations are automatically stripped before egress.

Deterministic
REG-KSA

Saudi Arabia PDPL & NCA ECC Compliance

Regional MENA Compliance

Fully aligned with the Saudi Personal Data Protection Law (Royal Decree M/19) and National Cybersecurity Authority Essential Cybersecurity Controls (ECC-1:2018).

Verified Active
REG-UAE

UAE Federal Law 45/2021 & DIFC/ADGM Interoperability

Regional MENA Compliance

Complies with UAE Federal Decree-Law No. 45 of 2021 on Personal Data Protection, with governance compatible with DIFC Data Protection Law No. 5 and ADGM DPR 2021.

Verified Active
REG-EG

Egypt Personal Data Protection Law (Law 151/2020)

Regional MENA Compliance

Adherent to Egypt Law No. 151 of 2020 on Personal Data Protection and National Telecommunications Regulatory Authority (NTRA) cyber frameworks.

Verified Active
VULN-01

Coordinated Vulnerability Disclosure & 24h Triage SLA

Audit & Vulnerability Management

We maintain a public vulnerability disclosure program with safe-harbor protections for security researchers and guaranteed 24-48h triage turnaround.

Enforced
SOVEREIGN COMPLIANCE

MENA Statutory Alignment Explorer

Primary Legal Sovereignty

Personal Data Protection Law (PDPL)

Royal Decree No. (M/19) • SDAIA
Full Processor Alignment

Strict data protection framework regulating personal data processing across the Kingdom, mandating purpose limitation, explicit consent standards, and stringent cross-border transfer controls.

Purpose Limitation

Search queries submitted to Dike are solely used for ephemeral grounding and never retained for secondary model training.

Cybersecurity Alignment

Mapped to NCA Essential Cybersecurity Controls (ECC-1:2018) for network architecture, identity controls, and operational monitoring.

Local Official Gazettes

Direct indexing of Umm Al-Qura official gazette and Royal Decrees with authentic statutory hierarchy.

Enterprise Compliance Artifacts Vault
On-Demand

Enterprise legal, risk, and security teams can request pre-compiled compliance documentation and custom Data Processing Addendums directly from our compliance team.

Enterprise DPA

Tailored Data Processing Addendum with standard MENA cross-border transfer clauses.

Request DPA
SOC 2 Type II Summary

Security, Availability, and Confidentiality control matrix mapping and executive report.

Request Report
Security Questionnaire

Pre-completed CAIQ & SIG Lite vendor risk assessment questionnaires for procurement.

Request CAIQ
Architecture Whitepaper

In-depth technical whitepaper on citation graphs, grounding pipelines, and threat models.

Request Paper
Vulnerability Disclosure
Safe Harbor Active

We welcome coordinated vulnerability disclosures from security researchers. We commit to responsive triage within 24–48 hours and will not pursue legal action against researchers acting in good faith.

Direct Security Contact<= 24h Initial Response