Security and Compliance at Dijit.app
At Dijit.app, data security and regulatory compliance are absolute priorities. As a B2B SaaS specialized in AI and OCR for enterprise document management, we ensure that all processed information remains protected through advanced and transparent measures.
Security and Compliance at Dijit.app is built on the highest European standards. Registered in Estonia since 2022, we leverage our status as an official Microsoft Azure partner to inherit industry-leading certifications. Our users and prospective customers can trust that we operate with full transparency and enterprise-grade protection measures.
Dijit.app is designed from the ground up to protect the sensitive business documents we process through OCR and AI. We use a Zero Trust architecture, where no entity accesses data by default without prior verification.
Our commitment to security
We implement multiple layers of protection to ensure the integrity and confidentiality of your business documents.
Identity and Access Management (IAM)
Access control under the principle of least privilege. Encrypted authentication and permission segmentation by teams and departments.
Data encryption
Protection in transit via TLS and at-rest encryption with advanced mechanisms. Secure secret management and periodic key rotation.
Multi-tenant isolation
Logical separation by organization. The Azure infrastructure operates with ISO/IEC 27001 certifications and SOC reports.
Logging and monitoring
Access logs, authentication events, and critical operations. Detection of anomalous behavior and full traceability.
Incident response
Structured procedure: identify, contain, eradicate, and recover. Notifications in line with GDPR and contractual requirements.
Business continuity
High availability and resilience in Azure. Backups, recovery, and restoration to minimize downtime.
Secure development and data residency
Best practices throughout the lifecycle and data hosted within the European Union.
Development lifecycle security (SDLC)
As a technology company, Dijit.app prioritizes secure practices throughout the development lifecycle: dependency review, known vulnerability control, code review, and change control. We aim to reduce typical web application risks such as data exposure, access control failures, injections, and insecure configurations.
We apply environment hardening practices, environment separation (development, staging, and production), and deployment controls with approvals and traceability. In addition, we promote a security culture within the team, including periodic training and internal processes that reduce human error.
Data residency in Europe (Azure EU)
Dijit.app is designed to operate with data storage and processing in Azure in Europe, enabling European customers to meet data residency and sovereignty requirements. Microsoft provides geographic regions in Europe to deploy cloud services and store customer information within the EU.
Additionally, Microsoft has developed the EU Data Boundary concept for Microsoft Cloud, with the goal of allowing commercial and public sector customers in Europe to store and process data within the EU and EFTA. At Dijit.app, this approach aligns with our commitment to keep data in Europe unless the customer requests otherwise or a applicable legal obligation exists. You can find more information in the official Azure compliance documentation.
GDPR compliance and European privacy
We apply privacy by design and privacy by default principles across all our operations, following the guidelines of the General Data Protection Regulation (GDPR).
Privacy principles
We minimize data, limit access, define reasonable retention periods, and avoid processing information that is not necessary to provide the service. We maintain a data inventory, a record of processing activities, and appropriate technical and organizational measures.
Roles: Controller and Processor
In a typical B2B SaaS scenario, the customer acts as the Data Controller and Dijit.app acts as the Processor. This role is formalized through a Data Processing Agreement (DPA) that details purposes, data types, and security measures.
EU Cloud Code of Conduct
Microsoft Azure adheres to the EU Cloud Code of Conduct, a European code aimed at implementing Article 28 GDPR requirements. This provides an additional layer of trust over the underlying cloud infrastructure.
Subprocessor management
We maintain a list of subprocessors and inform customers as established in the DPA. When new subprocessors are added, we assess risks and review contractual terms aligned with the European privacy framework.
Microsoft Azure Partner
Inherited certifications and evidence
Dijit.app benefits from the security and compliance controls built into Microsoft Azure, an environment with widely recognized audits and certifications. Azure certifications cover the cloud platform and audited services, and Dijit.app complements these assurances with its own controls, internal policies, and contractual commitments. See Azure certifications for more details.
Contractual transparency
To facilitate evaluation by legal, compliance, IT, and security teams, we provide clear and up-to-date documentation.
Privacy Policy
Collected data, purposes, and rights
Data Processing Agreement (DPA)
B2B contract, technical measures, and subprocessors
Terms of Service
Scope, limitations, and responsibilities
Cookie Policy
Categories, purposes, and management
Security Page
This page as a living resource
Subprocessor List
Technology providers used
Recommended practices for customers
Shared responsibility means our customers should also maintain good security practices.
✓ Manage users and access
Enable MFA for all accounts, remove inactive users, and review permissions regularly.
✓ Define internal policies
Establish document classification, retention, and access policies by role. Ensure only authorized personnel upload sensitive documents.
✓ Configure secure integrations
Protect API keys, restrict IPs where applicable, apply credential rotation, and log integration access.
✓ Assess DPIA when appropriate
When AI/OCR use involves large-scale processing or special categories, consider a DPIA based on the context.
Advanced security options for enterprise
Additional capabilities tailored to corporate needs, available depending on plan or agreement.
SSO / SAML / OIDC
Integration with corporate identity provider
Configurable retention
Retention and scheduled deletion policies
Enhanced auditing
Expanded logs and SIEM integration
Dedicated environments
Isolated deployments in Azure
Transparency: no in-house certification yet
Dijit.app is a startup in a growth phase and currently does not have its own external certifications such as ISO/IEC 27001. This transparency is deliberate: trust is built with verifiable evidence, clear communication, and consistent controls. While we move toward formal certifications, we implement equivalent controls, document operational evidence, and rely on Azure certifications to cover the infrastructure foundation.
Do you have questions about security or compliance?
For requests related to security, privacy, vendor questionnaires, assessment processes, or specific data residency requirements, our team is available to help.
To exercise data protection rights, report incidents, or request additional compliance information, use the contact channel indicated in the Privacy Policy.
This page is updated as Dijit.app adds new measures, enterprise features, and certifications. Last updated: January 2026.