Security at Dium, as it actually works.

What protects your community's data today, what we have not done yet, and how to reach us.

Last updated [email protected]
Draft for review. Confirm bracketed items and have counsel review before publishing.

Controls in place today

Each item below is something the Dium code does now. We list it so you can check it, not to sound impressive.

Encrypted in transit

Dium is served over HTTPS. Every sign-in cookie is marked Secure, so browsers only send it over an encrypted connection. [Confirm minimum TLS version, e.g. TLS 1.2+]

Locked-down session cookies

Session cookies are HttpOnly, so page scripts cannot read them, and SameSite=Lax. They expire after 30 days. Only a few display flags, such as signed-in status and your display name, are readable by page scripts.

Request forgery and framing

The app issues a CSRF token and checks it on requests that carry one. App pages send X-Frame-Options: DENY, nosniff and a strict Content Security Policy.

Rate limits

Per-IP limits apply to every API. Tighter limits apply to posting replies (30 a minute), sending DMs (30 a minute), filing reports (10 a minute) and uploads (20 a minute).

Scoped partner keys

Partner API keys are checked with a constant-time compare and carry scopes, so a key can be limited to the actions it needs. Keys go in the X-Api-Key header.

Account takeover guards

Email changes pushed from the profile service are logged but not applied. Placeholder accounts that have no identity key cannot be claimed with an email cookie alone.

No open redirects

After sign-in, Dium only redirects to hosts on a fixed allowlist. Anything else is refused.

Upload limits

Uploads are limited to common image types and PDF, at most 3 MB each. Rich text is cleaned of unsafe tags before it is stored.

Closed internal paths

Server folders for caches, logs, internal tools and shared code return 403 to the web. The browser is also told not to grant camera, microphone or location access to Dium pages.

Sign-in and payments run on named providers.

Dium never asks for a password, and card details are never typed into a Dium form.

Sign-in with Werify

Members sign in through Werify (werify.ai) with an email code or a social account. Partners can also send members in with a one-time token that expires after 5 minutes and works once.

Identity from Moat

Your name and avatar come from your Moat profile (moat.page). Dium keeps a copy for display and updates it when you edit Moat.

Payments with Werify Paywall

Paid plans check out on Werify Paywall. Dium signs each checkout request with HMAC-SHA256 and verifies the signed reply before it upgrades a Flow. Dium stores the order ID, plan, amount and status. [Confirm Werify Paywall's PCI DSS status and that no card data comes back to Dium]

Infrastructure and data handling

AreaWhat we can say today
Hosting provider and region[Provider name, region (e.g. US East), and a link to their SOC 2 / ISO 27001 report page]
DatabaseApp servers reach the database only through an internal HTTPS proxy operated by TAO.ai. There is no direct database connection from app code. [Confirm where the database runs and who operates it]
Encryption at rest[Confirm whether database disks, backups and uploaded files are encrypted at rest, and by whom]
Backups[Frequency, retention period, location, and whether restores are tested]
Staff access[Who at Dium can reach production data, whether staff MFA is required, and how often access is reviewed]
Logging and monitoring[What is logged, how long logs are kept, and who is alerted]
Real-time and emailLive updates run through Echo, and email is sent through LNBOX. Both are TAO.ai services. See the subprocessor list for details.
Direct messages are stored on Dium's servers. They are not end-to-end encrypted. See who sees what for when anyone other than the people in a conversation can read them.
Compliance status

No certifications yet, and we say so

We do not currently hold a SOC 2 report, an ISO 27001 certificate or any other security certification, and Dium is not built for health records or payment card data. [Confirm before publishing: we are aligning our controls with the SOC 2 Trust Services Criteria] We will update this page if and when an audit begins.

Incidents

If something goes wrong

We post service problems on the status page. If a security incident affects your data, we will tell affected Flow owners [notification window, e.g. within 72 hours of confirming a breach, matching the DPA] by email, with what happened and what we are doing.

Reviews

Security questionnaire on request

Buying for a company or an event? Email [email protected] and we will fill in your security questionnaire. [Confirm turnaround time, e.g. 10 business days]

Research

Found a vulnerability?

Our vulnerability disclosure policy explains scope and safe harbor. We acknowledge reports within 3 business days. Machine-readable contact details are in security.txt.