Skip to content
DIVEX — home

Trust

Security you can check,not just read about.

Who we are, how we treat your systems and data, and the safeguards running on this website, stated plainly and only where we can back them up.

Company

Who you areworking with.

A Romanian limited company, registered with the National Trade Register Office. The same details appear on every contract and invoice.

Company
DIVEX S.R.L.
Tax ID (CUI)
49953093
Trade Register
J2024008045403
EUID
ROONRC.J2024008045403
Registered office
Splaiul Independenței nr. 202B, camera 42, Sector 6, Bucharest

Client systems

How we handleyour access and data.

The defaults on every project. Anything stricter your organisation needs is agreed in writing before work begins.

Only the access a task needs

Individual accounts instead of shared logins, limited to what the work requires, and removed when the work ends.

Your accounts, your keys

Systems run in accounts your company owns. The access you give us, and the passwords and keys of the systems we build, are kept in a password manager or the platform's secret store, never in code, email or chat.

Data kept in scope

Your data is used only for the project it was shared for, is never used to train AI models, and stays in the EU where the project requires it.

Confidentiality in writing

An NDA before you share anything sensitive, and a data processing agreement wherever we process personal data on your behalf.

Security built in

Security headers, input validation, rate limits and dependency updates are part of the build, not a phase that comes later.

Incidents reported, not hidden

If something goes wrong on a system we operate, you hear it from us first: what happened, what was affected and what we changed.

This website

The same standard,on our own site.

Most of this can be checked from your browser's developer tools.

  • Processed in the EU

    Pages are served from Vercel's global network. Forms, bookings and the assistant run in its Frankfurt region.

  • No tracking cookies

    Analytics are first-party and cookieless. No advertising pixels and no third-party scripts, so there is no cookie banner to click through.

  • Strict security headers

    HTTPS enforced with HSTS, a Content Security Policy, and protection against framing and content sniffing on every response.

  • Forms protected from abuse

    Every form has invisible bot detection and rate limits, so it stays easy for people and expensive for scripts.

  • Confirmed from your inbox

    Bookings and newsletter sign-ups take effect only after you confirm by email, through encrypted links that expire.

  • An assistant that does not keep chats

    The AI assistant answers only from this site's content. We do not store conversations; we log only usage counts, to control cost.

Providers

Who processes datafor this website.

The services this website relies on and what each of them receives. The legal basis and retention periods are set out in the privacy policy.

  • Vercel

    Used for
    Hosting, cookieless analytics, access to AI models
    Receives
    Requests to the site, aggregate usage, questions sent to the assistant
  • Resend

    Used for
    Confirmation and reply emails
    Receives
    Your name, email address and the email itself
  • Google Workspace

    Used for
    Company email and the booking calendar
    Receives
    Messages you send us and the meetings you book
  • Google and OpenAI

    Used for
    The language models behind the assistant, through Vercel
    Receives
    The questions typed into the assistant

Report a vulnerability

Found a security issue?Tell us first.

Write to hello@divex.ai with what you found and how to reproduce it. We confirm receipt within two working days and keep you informed while we fix it.

Please do not access data that is not yours or degrade the service while testing, and give us reasonable time to fix the issue before disclosing it.

Questions

What securityreviews ask.

Are you ISO 27001 or SOC 2 certified?

No, and we will not imply otherwise. We complete security questionnaires and explain exactly how the practices on this page apply to your project.

Will you sign a data processing agreement?

Yes. Where we process personal data on your behalf, an agreement under Article 28 of the GDPR is part of the contract.

Where will our data be stored?

Where the project requires it, in EU regions of the providers you choose. Before a system goes live we document which services receive which data.

Do you use our data to train AI models?

No. When a project uses AI models, we choose providers and settings that do not train on your data, and we name them before they are used.

Who has access to our systems?

Only the people working on your project, each with their own account. Because that access lives in your accounts, you can see it and revoke it at any time.

Next step

Security questionsbefore you sign?

Send them over. We answer in writing, including when the answer is no.