Trust
Security you can check,not just read about.
Who we are, how we treat your systems and data, and the safeguards running on this website, stated plainly and only where we can back them up.
Company
Who you areworking with.
A Romanian limited company, registered with the National Trade Register Office. The same details appear on every contract and invoice.
- Company
- DIVEX S.R.L.
- Tax ID (CUI)
- 49953093
- Trade Register
- J2024008045403
- EUID
- ROONRC.J2024008045403
- Registered office
- Splaiul Independenței nr. 202B, camera 42, Sector 6, Bucharest
- hello@divex.ai
- Phone
- +40 750 457 957
Client systems
How we handleyour access and data.
The defaults on every project. Anything stricter your organisation needs is agreed in writing before work begins.
Only the access a task needs
Individual accounts instead of shared logins, limited to what the work requires, and removed when the work ends.
Your accounts, your keys
Systems run in accounts your company owns. The access you give us, and the passwords and keys of the systems we build, are kept in a password manager or the platform's secret store, never in code, email or chat.
Data kept in scope
Your data is used only for the project it was shared for, is never used to train AI models, and stays in the EU where the project requires it.
Confidentiality in writing
An NDA before you share anything sensitive, and a data processing agreement wherever we process personal data on your behalf.
Security built in
Security headers, input validation, rate limits and dependency updates are part of the build, not a phase that comes later.
Incidents reported, not hidden
If something goes wrong on a system we operate, you hear it from us first: what happened, what was affected and what we changed.
This website
The same standard,on our own site.
Most of this can be checked from your browser's developer tools.
Processed in the EU
Pages are served from Vercel's global network. Forms, bookings and the assistant run in its Frankfurt region.
No tracking cookies
Analytics are first-party and cookieless. No advertising pixels and no third-party scripts, so there is no cookie banner to click through.
Strict security headers
HTTPS enforced with HSTS, a Content Security Policy, and protection against framing and content sniffing on every response.
Forms protected from abuse
Every form has invisible bot detection and rate limits, so it stays easy for people and expensive for scripts.
Confirmed from your inbox
Bookings and newsletter sign-ups take effect only after you confirm by email, through encrypted links that expire.
An assistant that does not keep chats
The AI assistant answers only from this site's content. We do not store conversations; we log only usage counts, to control cost.
Providers
Who processes datafor this website.
The services this website relies on and what each of them receives. The legal basis and retention periods are set out in the privacy policy.
Vercel
- Used for
- Hosting, cookieless analytics, access to AI models
- Receives
- Requests to the site, aggregate usage, questions sent to the assistant
Resend
- Used for
- Confirmation and reply emails
- Receives
- Your name, email address and the email itself
Google Workspace
- Used for
- Company email and the booking calendar
- Receives
- Messages you send us and the meetings you book
Google and OpenAI
- Used for
- The language models behind the assistant, through Vercel
- Receives
- The questions typed into the assistant
Report a vulnerability
Found a security issue?Tell us first.
Write to hello@divex.ai with what you found and how to reproduce it. We confirm receipt within two working days and keep you informed while we fix it.
Please do not access data that is not yours or degrade the service while testing, and give us reasonable time to fix the issue before disclosing it.
Questions
What securityreviews ask.
Are you ISO 27001 or SOC 2 certified?
No, and we will not imply otherwise. We complete security questionnaires and explain exactly how the practices on this page apply to your project.
Will you sign a data processing agreement?
Yes. Where we process personal data on your behalf, an agreement under Article 28 of the GDPR is part of the contract.
Where will our data be stored?
Where the project requires it, in EU regions of the providers you choose. Before a system goes live we document which services receive which data.
Do you use our data to train AI models?
No. When a project uses AI models, we choose providers and settings that do not train on your data, and we name them before they are used.
Who has access to our systems?
Only the people working on your project, each with their own account. Because that access lives in your accounts, you can see it and revoke it at any time.
Next step
Security questionsbefore you sign?
Send them over. We answer in writing, including when the answer is no.

