Security & Compliance

Diliguard's security architecture and compliance posture. Data handling, GDPR compliance, encryption standards, and configurable retention policies.

SEO_Title: “Diliguard Security & Compliance | GDPR, Data Privacy & Infrastructure”

SEO_Description: “Diliguard’s security architecture and compliance posture. Data handling, GDPR compliance, encryption standards, and configurable retention policies.”

Primary_Keyword: “Diliguard Security Compliance”

Secondary_Keywords: [“GDPR compliance software”, “AML data security”, “enterprise data privacy”]

# Security & Compliance

## SECTION 1: Hero

**Headline:** How Diliguard Handles Data.

**Subheadline:** Diliguard processes sensitive corporate and personal intelligence data on behalf of regulated financial institutions. This page details the data sourcing model, infrastructure architecture, and regulatory compliance posture that govern every query the platform processes.

**CTA:** Request Security Documentation

## SECTION 2: Data Access & Sourcing

Diliguard connects directly to official government registries, regulatory authority APIs, and verified OSINT sources. Every intelligence output is traceable to a specific primary source. Clients can audit the origin of every data point Diliguard returns.

Diliguard does not purchase data from third-party data brokers or maintain a proprietary copy of registry data. Outputs always reflect the live state of the underlying source at the time of the query.

## SECTION 3: Data Handling Principles

*(Design: 4-item icon grid)*

**No Training Use**

Client-submitted data and intelligence outputs are never used for AI model training, internal analytics, or any third-party data enrichment. Data submitted to Diliguard is processed to produce a result, then retained only under the client’s configured policy.

**Configurable Retention**

Clients configure their own data retention policies within the platform. Investigation outputs can be set to auto-delete after a defined period. Diliguard does not impose a default retention period beyond what is required for audit trail compliance.

**Encryption in Transit and at Rest**

All data is encrypted in transit using TLS 1.3 and encrypted at rest using AES-256. This applies to all API traffic, portal sessions, and stored intelligence reports.

**Role-Based Access Controls**

Enterprise clients restrict which users can run specific query types, access specific report categories, or export investigation data. All access events are logged to an immutable audit trail.

## SECTION 4: Regulatory Compliance

**GDPR**

Diliguard operates as a data processor under GDPR for EU-based clients. A Data Processing Agreement (DPA) is available for all enterprise accounts. Data residency options ensure EU client data is processed and stored within EU-jurisdiction infrastructure.

**AML Regulatory Alignment**

Diliguard’s screening outputs align with FATF recommendations, FinCEN guidance, and the EU Anti-Money Laundering Directives (AMLD5 and AMLD6). The platform supports a client’s existing AML compliance program; it does not replace it.

**Audit Trail**

Every query, result, and access event is logged with a timestamp, user identifier, and data source reference. These logs are retained for a minimum of seven years for regulatory audit purposes, or longer under custom enterprise configurations.

## SECTION 5: Infrastructure

**Cloud Infrastructure**

Diliguard operates on enterprise-grade cloud infrastructure with multi-region redundancy. Clients requiring data residency within specific jurisdictions, including the EU and UK, can request region-locked deployment configurations.

**API Security**

All API access is authenticated via API key with optional IP allowlist enforcement. Webhook payloads are signed using HMAC-SHA256 for integrity verification. Rate limiting and request throttling protect against unauthorized bulk extraction.

**Incident Response**

Diliguard maintains a documented incident response plan. In the event of a data incident, affected clients are notified within 72 hours in accordance with GDPR Article 33 obligations.

## SECTION 6: Requesting Documentation

Enterprise clients and procurement teams can request the following directly from Diliguard’s compliance team:

– Data Processing Agreement (DPA)

– Sub-Processor List

– Security Architecture Overview

– Penetration Test Executive Summary (NDA required)

– Business Continuity and Disaster Recovery Plan

**CTA:** Request Documentation → [Contact](/contact)