Security built for enterprise agent workloads
Agent infrastructure runs close to production systems. We design Diaflow with isolation, encryption, and auditability as first-class requirements, not afterthoughts.
Security pillars
Encryption
All data encrypted at rest (AES-256) and in transit (TLS 1.2 minimum). API keys stored as hashed tokens, never in plaintext. Memory store contents encrypted per tenant.
Tenant Isolation
Every run executes in an isolated context. Working memory is scoped per run; episodic and semantic memory are scoped per account. Cross-tenant access is architecturally prevented.
Access Controls
Scoped API keys (read-only, execute-only, admin). RBAC for team seats on Pro and Enterprise plans. SSO/SAML integration available. All access logged.
Audit Logs
Every API call, run start/end, key creation, and user action is logged. Audit logs are immutable, exportable as CSV, and available to Enterprise customers via webhook stream.
Data Residency
Singapore-region deployment available for Enterprise customers. Data stays within the Singapore AWS region, supporting PDPA obligations for Singapore-headquartered organizations.
Vulnerability Response
We maintain a responsible disclosure process. Security reports go to [email protected]. We target acknowledgment within 24 hours and resolution within 30 days for critical issues.
PDPA and data handling
Diaflow is designed with Singapore's Personal Data Protection Act (PDPA) in mind. We are working toward formal PDPA compliance certification and will announce when complete.
Current practices include: data minimization (we collect only what's needed for service delivery), retention limits (run traces retained 90 days by default; configurable), purpose limitation (data used only for operating the Diaflow service), and user rights support (data access and deletion requests handled within 30 days).
Enterprise customers can sign a formal Data Processing Agreement (DPA) and access our technical security documentation package. Contact us to initiate that process.
Security FAQ
Security questions? Talk to us.
We respond to every security inquiry within 1 business day.