Security at Dium, as it actually works.
What protects your community's data today, what we have not done yet, and how to reach us.
Controls in place today
Each item below is something the Dium code does now. We list it so you can check it, not to sound impressive.
Encrypted in transit
Dium is served over HTTPS. Every sign-in cookie is marked Secure, so browsers only send it over an encrypted connection. [Confirm minimum TLS version, e.g. TLS 1.2+]
Locked-down session cookies
Session cookies are HttpOnly, so page scripts cannot read them, and SameSite=Lax. They expire after 30 days. Only a few display flags, such as signed-in status and your display name, are readable by page scripts.
Request forgery and framing
The app issues a CSRF token and checks it on requests that carry one. App pages send X-Frame-Options: DENY, nosniff and a strict Content Security Policy.
Rate limits
Per-IP limits apply to every API. Tighter limits apply to posting replies (30 a minute), sending DMs (30 a minute), filing reports (10 a minute) and uploads (20 a minute).
Scoped partner keys
Partner API keys are checked with a constant-time compare and carry scopes, so a key can be limited to the actions it needs. Keys go in the X-Api-Key header.
Account takeover guards
Email changes pushed from the profile service are logged but not applied. Placeholder accounts that have no identity key cannot be claimed with an email cookie alone.
No open redirects
After sign-in, Dium only redirects to hosts on a fixed allowlist. Anything else is refused.
Upload limits
Uploads are limited to common image types and PDF, at most 3 MB each. Rich text is cleaned of unsafe tags before it is stored.
Closed internal paths
Server folders for caches, logs, internal tools and shared code return 403 to the web. The browser is also told not to grant camera, microphone or location access to Dium pages.
Sign-in and payments run on named providers.
Dium never asks for a password, and card details are never typed into a Dium form.
Sign-in with Werify
Members sign in through Werify (werify.ai) with an email code or a social account. Partners can also send members in with a one-time token that expires after 5 minutes and works once.
Identity from Moat
Your name and avatar come from your Moat profile (moat.page). Dium keeps a copy for display and updates it when you edit Moat.
Payments with Werify Paywall
Paid plans check out on Werify Paywall. Dium signs each checkout request with HMAC-SHA256 and verifies the signed reply before it upgrades a Flow. Dium stores the order ID, plan, amount and status. [Confirm Werify Paywall's PCI DSS status and that no card data comes back to Dium]
Infrastructure and data handling
| Area | What we can say today |
|---|---|
| Hosting provider and region | [Provider name, region (e.g. US East), and a link to their SOC 2 / ISO 27001 report page] |
| Database | App servers reach the database only through an internal HTTPS proxy operated by TAO.ai. There is no direct database connection from app code. [Confirm where the database runs and who operates it] |
| Encryption at rest | [Confirm whether database disks, backups and uploaded files are encrypted at rest, and by whom] |
| Backups | [Frequency, retention period, location, and whether restores are tested] |
| Staff access | [Who at Dium can reach production data, whether staff MFA is required, and how often access is reviewed] |
| Logging and monitoring | [What is logged, how long logs are kept, and who is alerted] |
| Real-time and email | Live updates run through Echo, and email is sent through LNBOX. Both are TAO.ai services. See the subprocessor list for details. |
No certifications yet, and we say so
We do not currently hold a SOC 2 report, an ISO 27001 certificate or any other security certification, and Dium is not built for health records or payment card data. [Confirm before publishing: we are aligning our controls with the SOC 2 Trust Services Criteria] We will update this page if and when an audit begins.
If something goes wrong
We post service problems on the status page. If a security incident affects your data, we will tell affected Flow owners [notification window, e.g. within 72 hours of confirming a breach, matching the DPA] by email, with what happened and what we are doing.
Security questionnaire on request
Buying for a company or an event? Email [email protected] and we will fill in your security questionnaire. [Confirm turnaround time, e.g. 10 business days]
Found a vulnerability?
Our vulnerability disclosure policy explains scope and safe harbor. We acknowledge reports within 3 business days. Machine-readable contact details are in security.txt.
Related policies
Vulnerability disclosure
Scope, safe harbor and how to report.
ReadWho sees what
What visitors, members, owners, sponsors and staff can see.
ReadPrivacy policy
What we collect, why, and your rights.
ReadData processing addendum
Processor terms for Flow owners and partners.
ReadSubprocessors
Every vendor that touches member data.
ReadStatus
Live service status and incident history.
Check