Dijit.app Dijit.app Documentation

Documentation/ Account and plan/ Account security

Account security

This page sets out where your data sits and how it is protected, and the habits around access that are down to your own company.

Hosting and compliance

HostingMicrosoft Azure servers in the European Union.
ComplianceGDPR.
EncryptionTLS 1.3, in transit and encrypted at rest.
Sign-inMulti-factor, by role.

The security architecture and the compliance detail are set out on Security and compliance.

What happens to your documents

Access control

What somebody can see is set by their role. Running the account, meaning users, the plan and billing, is for administrators only.

Documents can also be split between users so each person works on their own. An administrator can go into another user's workspace in the same company; that is flagged on screen the whole time it is happening, and it does not last indefinitely.

The session in the browser

The session stays open in the browser until you sign out or it expires. It matters to anyone with physical access to the machine.

The application does not leave technical information about your data or internal addresses in the browser, and it defends against attempts to embed or tamper with the site from elsewhere.

What we advise

When someone leaves

When a person leaves the organisation, remove their user from user management. It happens at once and cannot be undone.

Check first whether they had documents redirected to them or a default project set, so that you can move it to somebody else.

↑ Back to top

Last reviewed: 29 September 2026 · The Dijit.app team