Documentation/ Account and plan/ Account security
Account security
This page sets out where your data sits and how it is protected, and the habits around access that are down to your own company.
On this page
Hosting and compliance
| Hosting | Microsoft Azure servers in the European Union. |
| Compliance | GDPR. |
| Encryption | TLS 1.3, in transit and encrypted at rest. |
| Sign-in | Multi-factor, by role. |
The security architecture and the compliance detail are set out on Security and compliance.
What happens to your documents
- The artificial intelligence models run inside Dijit.app's own Azure estate.
- Customer documents are never used to train models.
- Processed documents are archived and can be opened from each record, with a trail of what was done to them.
Access control
What somebody can see is set by their role. Running the account, meaning users, the plan and billing, is for administrators only.
Documents can also be split between users so each person works on their own. An administrator can go into another user's workspace in the same company; that is flagged on screen the whole time it is happening, and it does not last indefinitely.
The session in the browser
The session stays open in the browser until you sign out or it expires. It matters to anyone with physical access to the machine.
The application does not leave technical information about your data or internal addresses in the browser, and it defends against attempts to embed or tamper with the site from elsewhere.
What we advise
- Change the first password. The one emailed at sign-up should go on the first sign-in.
- Always sign out on a shared machine.
- Sign out when you finish on a machine that is not yours.
- One user per person. Shared credentials make it impossible to say who did what.
- Give the smallest role that works. The Client role is enough for someone who only brings documents in.
- Hand out generated passwords over something secure, and never reuse them.
When someone leaves
When a person leaves the organisation, remove their user from user management. It happens at once and cannot be undone.
Check first whether they had documents redirected to them or a default project set, so that you can move it to somebody else.