Company / Trust & Security

Security for the most sensitive documents in energy. Stored in Zürich, Switzerland. Encrypted. Never used to train AI.

Data rooms, contracts and financial models decide transactions. Yours are stored in Zürich, encrypted in transit and at rest, never used to train AI, and reachable only by the people you name.

  • Stored in Zürich, Switzerland
  • TLS 1.3 in transit · AES-256 at rest
  • Never used to train AI — contractual
  • GDPR · Swiss FADP
  • NDA before any upload
  • Row-level access, enforced by the database
  • Expert-approved due diligence reports
  • ISO/IEC 27001 · SOC 2 Type II certified infrastructure
Where your data lives

Stored in Switzerland. Served from Germany.

Zürich, Switzerland

Client documents, generated reports and backups.

Frankfurt, Germany

Database, authentication and application servers.

Network edge

TLS termination and DDoS protection. No client documents are stored at the edge.

AI analysis runs under enterprise terms with contractual no-training and no-retention commitments: nothing you upload is used to train a model, and nothing is kept for the provider's own purposes. Your documents remain stored in Switzerland, and no client document, data-room file or report is ever sent to any other AI provider.

How an engagement handles your data

Four steps, in this order, every time.

  1. Step 1

    1NDA first

    A mutual non-disclosure agreement is signed before any confidential data moves.

  2. Step 2

    2Sealed transfer

    Documents go directly into your private, encrypted workspace.

  3. Step 3

    3Scoped access

    Only the people you name — on your side and ours — can reach the engagement. Access is granted per project.

  4. Step 4

    4Your deliverable

    Outputs belong to you and are delivered through the same controlled workspace.

The controls

What protects your data.

The same technical and organisational measures we commit to in writing with every client.

Access

Role-based access on the principle of least privilege, with individual named accounts for everyone who touches client data. Tenant data segregated at the database layer by row-level policies the database enforces itself — a request carrying one client's identity cannot read another's rows.

Documents

Held in private storage that is not publicly readable. Served only through time-limited signed links, issued after the backend has verified that the requesting user is entitled to that specific file.

Encryption

TLS 1.3 or higher in transit. AES-256 at rest. Keys managed by the infrastructure providers.

Integrity and logging

Every change to client data is attributable to an authenticated user. Administrative and privileged operations are logged. Data-modifying interfaces validate their inputs.

Resilience

Redundant infrastructure across availability zones. Continuous database backup with point-in-time recovery. Restoration tested periodically.

Change and review

Security review is part of the change process for any component that handles client data or authentication. Automated checks run before every deployment; findings rated as errors are fixed before release. Dependencies and configuration are scanned continuously.

People

Written confidentiality obligations for everyone who works with us, surviving their departure. Annual data-protection training.

AI accountability

Speed and depth from AI. Judgement from industry experts.

AI provides the speed and the depth; human industry experts provide the judgement — and approve every due diligence report. Every supervised due diligence report is reviewed and approved by a qualified advisor before it is issued, and says so on its face. Self-service analyses are yours to run at any time, built to support the professional judgement of the people using them.

Certifications

Built to the standard, run on certified infrastructure.

Our security controls are built to the ISO/IEC 27001 and SOC 2 control families — access control, encryption, logging, incident response, vendor management, backup and personnel security — and are written into every agreement we sign.

The infrastructure that stores and processes your data is independently certified: SOC 2 Type II across every provider that stores or processes client data, and ISO/IEC 27001 for document storage and the database.

  • Document storageISO/IEC 27001 · SOC 2 Type IIZürich, Switzerland
  • DatabaseISO/IEC 27001 · SOC 2 Type IIFrankfurt, Germany
  • Application hostingSOC 2 Type IIFrankfurt, Germany
Your data, your control

Yours to keep.

  • Ownership

    You own everything you upload and everything we produce for you.

  • Export

    Every report and project can be exported at any time.

  • Retention

    Your documents, analyses and reports stay available to you for as long as you use the platform. Nothing expires, and nothing is deleted without your instruction.

  • Confidentiality

    Your projects are visible only to the people you invite. Access is granted per project and can be withdrawn at any time.

See it on one of your own projects.

Bring a live data room. Every document stays in Switzerland from the first upload, and the report arrives approved by a qualified advisor.

Questions about security: [email protected]

    Trust & Security — where your data lives and who can reach it | Diligent Energy AI