KITE 2025 New Product Award — Local IT | SACEEC

Your GRC data is in safe hands

Every control, working in the product

Security is built into Dimeri at every layer — so your governance, risk, and compliance data stays confidential, available, and tamper-proof.

app.dimeri.ai

Granular access

Everyone on your team sees exactly what they should — and nothing they shouldn't.

Certified & Compliant

Aligned with the frameworks that matter

Dimeri is designed to meet and align with leading regulatory and governance frameworks relevant to governance, risk, and compliance.

POPIA
Aligned

Practices aligned with the Protection of Personal Information Act data protection principles.

GDPR
Aligned

Data minimization, export, and deletion capabilities aligned with EU GDPR principles.

ISO 27001
Aligned

Security practices aligned with ISO 27001 information security management standards.

ISO 31000
Aligned

Platform built around ISO 31000 enterprise risk management principles.

COSO ERM
Aligned

Supports COSO framework mapping across risk registers and controls.

Privacy by Design
Principle

Privacy controls built into the platform architecture from the ground up, not added as an afterthought.

Trusted Data Storage

Your data, protected by design

As a GRC platform handling sensitive governance, risk, and compliance data, we go beyond baseline compliance with security-first defaults at the storage layer.

Encryption everywhere

TLS encryption protects data in transit on every connection, and your data is encrypted at rest by our managed database infrastructure.

Strict workspace isolation

Every query is scoped to the authenticated user's workspace. Tenants are fully separated, so you only ever see your own data.

No training on your data

Customer data is never used to train AI models. Your data stays yours.

Full Ownership & Flexibility

You stay in control of your data

Retention, governance, access, and identity are all configurable and transparent.

Data retention & deletion

Export or permanently delete your workspace data anytime. We only ever hold the information you choose to put into Dimeri — we never harvest, sell, or mine your data.

Full audit visibility

Every create, update, delete, and login is recorded with timestamp and user attribution. Owners can view the complete activity trail.

Enterprise SSO

SAML 2.0 single sign-on works with all major identity providers. Deprovisioning in your identity provider instantly blocks access.

Role-based access control

A four-tier permission model covering Owner, Admin, Member, and Viewer roles, enforced at both the API and interface layers.

Security Controls

Continuously monitored across every domain

Comprehensive protection of your governance, risk, and compliance data, enforced from the API layer up.

Product Security

Authentication enforcement
Access to every part of the platform requires authentication, with sessions that expire automatically.
Session management
Sessions are managed securely, and access is revoked the moment a user logs out.
Single Sign-On (SSO)
Single sign-on integrates with all major enterprise identity providers.
Rate limiting
Requests are rate limited to prevent brute force attempts and abuse.

Data Security

Encryption in transit & at rest
Your data is encrypted both in transit and at rest.
Workspace isolation
Each workspace is fully isolated, so you only ever access your own data.
Automated backups
Data is backed up automatically with reliable recovery.
Data minimization
Only the data necessary for GRC functionality is collected, with no unnecessary personal information.

Application & Network

Input validation
All inputs are validated server-side to prevent injection and malformed data.
Content sanitization
User-generated content is sanitized against an allowlist before it is rendered.
Hardened headers
Security response headers are enforced on every request.
Encrypted transport
All traffic is forced over HTTPS with strict cross-origin controls.

Audit & Operations

Activity audit trail
Every action is logged with timestamp, user, action type, and affected resource.
Structured logging
Structured logging with module-level tracing across services.
Offboarding
User suspension immediately revokes access and invalidates active sessions.
Incident response
Documented procedures for incident identification, containment, and resolution.
AI Posture

Transparent, opt-in, never trained on your data

Dimeri uses AI to enhance risk analysis, recommendations, and report drafting, with privacy, transparency, and user control as core principles.

Multi-provider approach: Dimeri works with multiple AI providers to deliver the best possible analysis. The provider used for a given request may change as we continuously evaluate model performance and reliability. All providers are held to the same data protection standards, and all AI outputs are advisory and subject to human review.
AI providersDimeri integrates with multiple leading enterprise AI providers. The active model may vary based on which delivers the most accurate and reliable output for a given analysis.
Human-in-the-loopAll AI-generated assessments, suggestions, and outputs require user review and explicit confirmation before being saved. AI outputs are advisory only.
Training on customer dataNo. Customer data is never used for AI model training, by Dimeri or any provider. Our provider agreements contractually prohibit training on customer inputs.
Data sent to AIOnly the specific context the user is actively working with, such as a risk description, control detail, or objective. Never bulk exports, full databases, or unrelated workspace data.
Output validationAll AI responses are parsed, validated against expected schemas, and sanitized before rendering. Malformed or unexpected outputs are rejected.
Opt-outAI features are entirely optional. Organizations can use the full Dimeri GRC platform without engaging any AI functionality.
FAQ

Frequently asked questions

Everything you need to know about how Dimeri protects your data.

All data is encrypted in transit and encrypted at rest by our database infrastructure. Each workspace is fully isolated, so users can only access data within workspaces they have been invited to. Role-based permissions ensure team members see only what they are authorized to.

Yes. Business plan customers can configure SAML single sign-on with any major identity provider through a self-service admin portal. Users are automatically provisioned into their workspace.

No. Customer data is never used for AI model training, by Dimeri or any of our AI providers. The AI assistant only processes the specific context you are working with, and this data is not retained by the provider after the request completes.

Dimeri uses a four-tier role model covering Owner, Admin, Member, and Viewer. Owners control workspace settings and member access, Admins manage content, Members create and edit, and Viewers have read-only access. All permissions are enforced at the API layer, not just the interface.

Workspace owners or admins can immediately suspend a user, which revokes all access and prevents further login. For SSO-enabled workspaces, deprovisioning in the identity provider automatically blocks access.

Dimeri's practices are aligned with the principles of both the South African Protection of Personal Information Act (POPIA) and the EU General Data Protection Regulation (GDPR). We practice data minimization and provide data export and deletion capabilities on request.

See Dimeri's security in action

Book a demo to walk through our controls, compliance posture, and data handling with our team.

Book a demo