Dictamen
Security & control

Designed for board-level sensitivity.

Dictamen holds the most consequential decisions in the organisation. The record must be private, scoped, and auditable from the first day.

Five pillars

How sensitivity is preserved.

01

Internal by default

No external exposure of strategic context. The record belongs to the organisation. No shared training. Strict tenant isolation, enforced and regression-tested in CI.

02

Reviewer & approver views

Visibility scoped by role across context, challenge, and final record. The same decision can be visible to an approver while sensitive context remains held to a smaller group.

03

Private context controls

Sensitive inputs — terms, counterparties, models — held under tighter constraints. Asymmetric disclosure during challenge is supported.

04

Append-only audit trail

Every approval, condition change, and reopening preserved and retrievable. Append-only, identity-attributed audit events on every state change. Time-stamped, attributable, and exportable.

05

Private deployment option

Can be structured as a dedicated single-tenant configuration where required. Region pinning available for UAE and KSA workloads.

Controls at a glance

Enterprise primitives, set up to default-private.

Encryption

TLS 1.3 in transit. AES-256 at rest. Customer-managed keys available on private deployment.

Identity

SSO via SAML 2.0 / OIDC. SCIM provisioning. MFA enforced via your identity provider (SAML/OIDC).

Data residency

EU and Middle East regions available. Region selection pinned per tenant.

Logging

Append-only, identity-attributed audit events on every state change. Exportable to enterprise SIEM.

Compliance

SOC 2 Type I program underway — report available under NDA on completion. Started March 2026.

Model posture

Model-agnostic. No customer content used to train base models. Vendor list disclosed in the trust pack.

Trust pack

A document, not a marketing page.

For enterprise IT and security review, we share a structured trust pack covering data flow, sub-processors, deployment topology, key management, and incident response. Available on request as part of the diagnostic.

Talk to us

Walk through the trust pack with our team.

Security & control — Dictamen