# Security & Compliance: Dike

_Last updated: August 17, 2026_

Dike provides the verified Arabic legal source layer for artificial intelligence. We engineer our platform with security, privacy, and regulatory compliance at the foundation, ensuring enterprise legal teams, financial institutions, and developers can safely ground mission-critical applications in MENA statutory authority.

## 1. Enterprise AI Data Governance & Zero-Retention

- **Zero Customer Training:** Prompts, search queries, document embeddings, and reasoning inputs submitted to Dike API endpoints are **never** used to train, fine-tune, or improve foundation models.
- **Data Isolation:** Customer requests are processed within isolated runtime execution environments with strict memory boundaries.
- **Retrieval Grounding Only:** Dike acts as a verifiable retrieval and reasoning layer against indexed public and authorized statutory authority. We do not persist proprietary enterprise context beyond ephemeral request lifecycles.
- **Configurable Request Logs:** Developer logs stored in the console are restricted to your authenticated account ID, with payload truncation protections and configurable retention periods.

## 2. Infrastructure & Network Security

- **Encryption in Transit:** All traffic to Dike REST (`https://api.dike.it.com`) and gRPC (`api.dike.it.com:9090`) endpoints is strictly encrypted using TLS 1.3 with modern cryptographic cipher suites.
- **DDoS & Edge Protection:** Edge perimeter defense powered by Cloudflare Enterprise with active Web Application Firewall (WAF) rules, rate limiting, and automated threat mitigation.
- **VPC Isolation & Zero Trust:** Backing databases, vector search indices, and citation graph traversal engines operate in private Virtual Private Clouds (VPCs) with zero direct public ingress and least-privilege network segmentation.

## 3. Identity, Access & Credential Management

- **Cryptographically Hashed API Keys:** Secret API keys are generated with high-entropy random bytes, stored as salted cryptographic hashes (SHA-256), and prefixed (`dk_live_...`) for automated secret scanning detection.
- **WebAuthn / Passkey Support:** Native FIDO2 hardware passkey authentication (Touch ID, Face ID, YubiKey) for developer portal access, providing phishing-resistant multi-factor security.
- **Session & Key Invalidation:** Immediate revocation capabilities for compromised API keys and automated session revocation upon credential rotation.

## 4. MENA Regional Regulatory Alignment

Dike is designed specifically for organizations operating under Middle East regulatory frameworks:

- **Kingdom of Saudi Arabia (KSA):**
  - Aligned with the **Personal Data Protection Law (PDPL)** enacted by Royal Decree No. (M/19) and SDAIA regulatory requirements.
  - Controls mapped to the **National Cybersecurity Authority (NCA) Essential Cybersecurity Controls (ECC-1:2018)**.
- **United Arab Emirates (UAE):**
  - Compliant with **Federal Decree-Law No. 45 of 2021** regarding Personal Data Protection.
  - Interoperable with **DIFC Data Protection Law No. 5 of 2020** and **ADGM Data Protection Regulations 2021**.
- **Arab Republic of Egypt:**
  - Adherent to **Law No. 151 of 2020** promulgating the Personal Data Protection Law.

## 5. Hallucination Guard & Citation Verification

- **100% Grounded Assurance:** Every citation generated by the Dike reasoning pipeline (`/v1/reason`) is deterministically verified against the retrieved statutory gazette corpus. Unverified or fabricated references are automatically stripped before the response reaches the client.
- **Immutable Citation Anchors:** Document references are resolved to canonical IDs with verifiable publication dates and official gazette citations.

## 6. Vulnerability Disclosure & Incident Response

We welcome responsible security research and vulnerability disclosures. If you discover a potential security issue in Dike's infrastructure, API, or web services, please notify us immediately.

- **Security Contact:** [security@dike.it.com](mailto:security@dike.it.com)
- **Triage SLA:** We acknowledge receipt within 24 hours and provide an initial assessment within 48 hours.
- **Safe Harbor:** We will not pursue legal action against security researchers who follow responsible disclosure guidelines, test only against their own accounts, and avoid data exfiltration or service disruption.

## Compliance Requests

Enterprise customers requiring custom Data Processing Addendums (DPA), vendor security assessments (CAIQ / SIG Lite), or SOC 2 alignment documentation can contact our compliance team at [compliance@dike.it.com](mailto:compliance@dike.it.com).
