
Enterprise Security, Privacy & Compliance Matrix
Explore Dike's real-time security posture: zero-retention AI governance, hardware-backed WebAuthn passkeys, and verified statutory compliance across Saudi Arabia, the UAE, and Egypt.
Searchable Security & Governance Controls
Zero Customer Data Retention for Foundation Model Training
AI & Data GovernanceEnterprise queries, prompts, document embeddings, and context payloads are strictly isolated. We never use customer data to train, fine-tune, or adapt foundation models.
Enterprise queries, prompts, document embeddings, and context payloads are strictly isolated. We never use customer data to train, fine-tune, or adapt foundation models.
# Verified Header: No Customer Retention Policy
# Header X-Dike-Zero-Retention: active is returned on every reasoning request
curl -I -X POST https://api.dike.it.com/v1/reason \
-H "Authorization: Bearer $DIKE_API_KEY" \
-H "Content-Type: application/json" \
-d '{"question":"مسؤولية الناقل الجوي"}'End-to-End Transport Encryption (TLS 1.3 & gRPC mTLS)
Cryptography & IngressAll traffic across public and private endpoints enforces TLS 1.3 with modern elliptic curve cipher suites (ECDHE-ECDSA-AES256-GCM-SHA384) and Perfect Forward Secrecy.
FIDO2 WebAuthn Hardware Passkeys & Salted Hashed Keys
Cryptography & IngressDeveloper portal sign-ins support phishing-resistant WebAuthn passkeys (Touch ID, Face ID, YubiKey). API secret keys are stored as salted SHA-256 hashes.
100% Grounded Deterministic Verification Filter
Statutory Hallucination GuardEvery citation emitted by the legal reasoning engine is deterministically verified against retrieved gazette texts. Unverified citations are automatically stripped before egress.
Saudi Arabia PDPL & NCA ECC Compliance
Regional MENA ComplianceFully aligned with the Saudi Personal Data Protection Law (Royal Decree M/19) and National Cybersecurity Authority Essential Cybersecurity Controls (ECC-1:2018).
UAE Federal Law 45/2021 & DIFC/ADGM Interoperability
Regional MENA ComplianceComplies with UAE Federal Decree-Law No. 45 of 2021 on Personal Data Protection, with governance compatible with DIFC Data Protection Law No. 5 and ADGM DPR 2021.
Egypt Personal Data Protection Law (Law 151/2020)
Regional MENA ComplianceAdherent to Egypt Law No. 151 of 2020 on Personal Data Protection and National Telecommunications Regulatory Authority (NTRA) cyber frameworks.
Coordinated Vulnerability Disclosure & 24h Triage SLA
Audit & Vulnerability ManagementWe maintain a public vulnerability disclosure program with safe-harbor protections for security researchers and guaranteed 24-48h triage turnaround.
MENA Statutory Alignment Explorer
Personal Data Protection Law (PDPL)
Royal Decree No. (M/19) • SDAIAStrict data protection framework regulating personal data processing across the Kingdom, mandating purpose limitation, explicit consent standards, and stringent cross-border transfer controls.
Search queries submitted to Dike are solely used for ephemeral grounding and never retained for secondary model training.
Mapped to NCA Essential Cybersecurity Controls (ECC-1:2018) for network architecture, identity controls, and operational monitoring.
Direct indexing of Umm Al-Qura official gazette and Royal Decrees with authentic statutory hierarchy.
Enterprise legal, risk, and security teams can request pre-compiled compliance documentation and custom Data Processing Addendums directly from our compliance team.
Tailored Data Processing Addendum with standard MENA cross-border transfer clauses.
Security, Availability, and Confidentiality control matrix mapping and executive report.
Pre-completed CAIQ & SIG Lite vendor risk assessment questionnaires for procurement.
In-depth technical whitepaper on citation graphs, grounding pipelines, and threat models.
We welcome coordinated vulnerability disclosures from security researchers. We commit to responsive triage within 24–48 hours and will not pursue legal action against researchers acting in good faith.