Your GRC data is in safe hands
Every control, working in the product
Security is built into Dimeri at every layer — so your governance, risk, and compliance data stays confidential, available, and tamper-proof.
Granular access
Everyone on your team sees exactly what they should — and nothing they shouldn't.
Aligned with the frameworks that matter
Dimeri is designed to meet and align with leading regulatory and governance frameworks relevant to governance, risk, and compliance.
Practices aligned with the Protection of Personal Information Act data protection principles.
Data minimization, export, and deletion capabilities aligned with EU GDPR principles.
Security practices aligned with ISO 27001 information security management standards.
Platform built around ISO 31000 enterprise risk management principles.
Supports COSO framework mapping across risk registers and controls.
Privacy controls built into the platform architecture from the ground up, not added as an afterthought.
Your data, protected by design
As a GRC platform handling sensitive governance, risk, and compliance data, we go beyond baseline compliance with security-first defaults at the storage layer.
TLS encryption protects data in transit on every connection, and your data is encrypted at rest by our managed database infrastructure.
Every query is scoped to the authenticated user's workspace. Tenants are fully separated, so you only ever see your own data.
Customer data is never used to train AI models. Your data stays yours.
You stay in control of your data
Retention, governance, access, and identity are all configurable and transparent.
Export or permanently delete your workspace data anytime. We only ever hold the information you choose to put into Dimeri — we never harvest, sell, or mine your data.
Every create, update, delete, and login is recorded with timestamp and user attribution. Owners can view the complete activity trail.
SAML 2.0 single sign-on works with all major identity providers. Deprovisioning in your identity provider instantly blocks access.
A four-tier permission model covering Owner, Admin, Member, and Viewer roles, enforced at both the API and interface layers.
Continuously monitored across every domain
Comprehensive protection of your governance, risk, and compliance data, enforced from the API layer up.
Product Security
Data Security
Application & Network
Audit & Operations
Transparent, opt-in, never trained on your data
Dimeri uses AI to enhance risk analysis, recommendations, and report drafting, with privacy, transparency, and user control as core principles.
| AI providers | Dimeri integrates with multiple leading enterprise AI providers. The active model may vary based on which delivers the most accurate and reliable output for a given analysis. |
| Human-in-the-loop | All AI-generated assessments, suggestions, and outputs require user review and explicit confirmation before being saved. AI outputs are advisory only. |
| Training on customer data | No. Customer data is never used for AI model training, by Dimeri or any provider. Our provider agreements contractually prohibit training on customer inputs. |
| Data sent to AI | Only the specific context the user is actively working with, such as a risk description, control detail, or objective. Never bulk exports, full databases, or unrelated workspace data. |
| Output validation | All AI responses are parsed, validated against expected schemas, and sanitized before rendering. Malformed or unexpected outputs are rejected. |
| Opt-out | AI features are entirely optional. Organizations can use the full Dimeri GRC platform without engaging any AI functionality. |
Frequently asked questions
Everything you need to know about how Dimeri protects your data.
All data is encrypted in transit and encrypted at rest by our database infrastructure. Each workspace is fully isolated, so users can only access data within workspaces they have been invited to. Role-based permissions ensure team members see only what they are authorized to.
Yes. Business plan customers can configure SAML single sign-on with any major identity provider through a self-service admin portal. Users are automatically provisioned into their workspace.
No. Customer data is never used for AI model training, by Dimeri or any of our AI providers. The AI assistant only processes the specific context you are working with, and this data is not retained by the provider after the request completes.
Dimeri uses a four-tier role model covering Owner, Admin, Member, and Viewer. Owners control workspace settings and member access, Admins manage content, Members create and edit, and Viewers have read-only access. All permissions are enforced at the API layer, not just the interface.
Workspace owners or admins can immediately suspend a user, which revokes all access and prevents further login. For SSO-enabled workspaces, deprovisioning in the identity provider automatically blocks access.
Dimeri's practices are aligned with the principles of both the South African Protection of Personal Information Act (POPIA) and the EU General Data Protection Regulation (GDPR). We practice data minimization and provide data export and deletion capabilities on request.
See Dimeri's security in action
Book a demo to walk through our controls, compliance posture, and data handling with our team.
Book a demo