Skip to content
Security & Trust

Your assistant knows a lot about you.
Here's how we keep it that way.

Security at Diali isn't a checklist page. It's the architecture. Every assistant runs alone in its own sandbox, on EU infrastructure, deletable whenever you choose.

KMSManaged encryption keys (Google Cloud KMS)
99.9%Uptime target
0Data sold or used to train models
EUHosted in Belgium (EU)
Our principles

How we think about security

One tenant, one sandbox

Every assistant runs in its own isolated Kubernetes namespace with locked-down pod security, its own service account, and network policies that keep it off our internal network, the cloud metadata server and every other tenant. Agent workloads run under kernel-level gVisor sandboxing on a dedicated node pool. Assistants cannot see each other. By construction, not by convention.

Community skills, with their audit status up front

Skills come from a public ecosystem, and a poisoned one is a real risk. Every skill in our catalog shows ClawHub's security review where one exists (a verdict, a plain-language summary of what it actually does, and the date it was checked) and says so when a skill hasn't been audited, all before you install. You pick which skills an assistant gets, and it runs them inside its own sandbox.

Encrypted at rest, keys under our control

Data is encrypted at rest with keys we manage in Google Cloud KMS: the database, file storage, even our own state. The keys are ours rather than cloud defaults, and access to them is audited.

Secrets never touch a config file

API keys and credentials live in Google Secret Manager, synced into your assistant's environment at runtime, scoped to that one tenant. Staff access is role-gated and audited; the admin plane sits behind network-level restrictions.

Patched on our clock, not yours

The runtimes move fast, and an upstream release can break a setup or carry a fix you need. We test each release on our own assistants before it reaches yours, then roll it out. Dependencies and base images are patched continuously, and images are scanned in CI before they ship.

Recoverable, not just isolated

Isolation protects an assistant from everything else. Backups protect it from itself. Snapshots run daily with 30 days of history, restore is one click, and you can take one on demand before a risky change. Included with the Large plan, an add-on below it.

EU-hosted, exportable, erasable

Your assistants and your data are hosted in Google Cloud europe-west1 (St. Ghislain, Belgium). You can export your assistant's data and memory, and deleting your account deletes the workload, the storage, and the secrets.

Access controls

Lock your assistant to specific users via allow-lists. Only the people you choose can interact with your assistant.

Restricted internal access

Only authorized Diali engineers can access infrastructure. All access is logged, audited, and reviewed.

Permissions

What Diali can and
cannot access

We are transparent about what we see when you use Diali.

What we access

Assistant configuration (name, tone, use cases) • Channel connection status • Your Diali account details • Billing information • Hosting health & uptime metrics

What we do not access

Your conversations: we don't read them. Only your dashboard chat history is stored, so you can see it across devices • Your channel contacts or history, which are processed only inside your assistant's isolated workspace • Your AI provider account • Data from your connected apps or integrations • We never sell your data or train models on it

EU Data Centereurope-west1 (Belgium)
Active
99.9% Uptime TargetMonitored 24/7
Active
Sandboxed Agent WorkspacesKernel-level gVisor isolation
Active
Private VPCNo access to our internal network
Active
Infrastructure

Built on secure
infrastructure

Infrastructure as code (Terraform + GitOps), reviewed before it ships. Every workload runs under its own identity (Workload Identity, no exported service-account keys), on a private VPC where assistants can reach the public web but never our internal network, the cloud metadata server or other tenants, with TLS everywhere.

Honest claims

What we actually guarantee

No security theatre, only what we can truly stand behind.

  • Encrypted in transit & at rest

    All communication between your device, our servers, and your assistant uses TLS 1.2+. Data stored on our servers is encrypted with AES-256. This is a technical guarantee we can verify and confirm.

  • Your assistant reads your messages to respond. That's how it works

    To reply intelligently, your assistant processes the content of messages. That happens through your AI provider, either on your own key (BYOK) or through Diali AI (managed), which forwards it via a third-party AI routing service to the model's developer, on Diali's account. Either way, Diali does not read conversation content or use it to train models.

  • 99.9% uptime target

    Our hosting infrastructure is designed for high availability. We target 99.9% monthly uptime. This is a target, not a contractual SLA.

Security FAQ

Common questions

  • No. Diali does not read your conversations or use them to train models. In BYOK mode your messages go to your AI provider on your own key; in managed mode they pass through Diali AI, which records only billing metadata (model, cost, status). Messages in your messaging apps are not stored by Diali. Conversations you hold in the dashboard chat, and messages between your assistants, are stored so you can see your history across devices; deleting a thread removes it from your history, and deleting the assistant erases them.

  • Your API key is stored in Google Secret Manager, encrypted at rest and scoped to your assistant. In managed mode your assistant only ever holds a revocable virtual key. You can remove your key at any time from your vault.

  • No. Diali never uses your data to train AI models. Your conversations belong to you. We never sell your data; we share it only with the processors listed in our Privacy Policy.

  • The workload is torn down and its storage and secrets are destroyed. Deleting your account does the same across everything you run.

  • Yes. Assistants can reach the public web (HTTP and HTTPS) to browse, search and use the tools you enable, but never our internal network, the cloud metadata server or other tenants.

  • Code runs inside your assistant's own gVisor-sandboxed workspace: kernel-level isolation, never on shared workers. Each assistant is isolated in its own Kubernetes namespace, so nothing it runs can reach another tenant.

  • Stored in Google Cloud europe-west1 (St. Ghislain, Belgium), encrypted at rest. Some processors (payments, AI providers, analytics) process data outside the EU under Standard Contractual Clauses; see the Privacy Policy.

Still have questions?

We're transparent about how we handle your data. Our team is here to answer any security question you have.