Security & Trust

Infrastructure visibility requires access to sensitive information. We take that responsibility seriously — with independent audits, zero-persistence credential handling, and a security-first engineering culture.

Certifications & compliance

🛡

SOC 2 Type II

Independently audited annually by Drata. Full report available to enterprise customers under NDA.

📋

ISO 27001

Certified information security management system covering all DiagramIQ cloud operations.

🇪🇺

GDPR Ready

Data Processing Agreements available. EU data residency option available on Enterprise plan.

💳

PCI DSS

Payment Card Industry compliance for all billing operations. No card data touches our infrastructure.

How we protect your data

🔑

Zero persistent credential storage

DiagramIQ uses short-lived, scoped read-only cloud credentials for every scan. We never store IAM keys, service principal secrets, or long-lived tokens.

🚫

No agents, no code access

Discovery works entirely via cloud-provider APIs. We never install agents, require VPN access, or touch your application code or source repositories.

🔒

Encryption everywhere

All data is encrypted at rest (AES-256) and in transit (TLS 1.3). Architecture diagrams and metadata are encrypted per-customer with dedicated keys.

🎯

Least-privilege by design

Our AWS, Azure, and GCP integration roles require only read-only permissions. We publish exact IAM policies so your security team can verify them independently.

🔍

Penetration testing

External pen tests are conducted quarterly by independent security firms. Findings are remediated within SLA and tracked in our public security changelog.

🤝

Responsible disclosure programme

We operate a managed bug bounty programme. Security researchers who discover vulnerabilities can report them at security@diagramiq.io and receive acknowledgement within 24 hours.

Data residency

United States (default)
AWS us-east-1 + us-west-2
Available on all plans. Multi-region replication for high availability.
European Union
AWS eu-west-1 + eu-central-1
Available on Pro and Enterprise plans. Data never leaves the EU.
Asia Pacific
AWS ap-southeast-1 + ap-northeast-1
Available on Enterprise plans. Contact sales to enable.

Questions about security?

Our security team responds within 24 hours.

Contact Security Team