This page explains how we build and run your workflows, and this website, to protect data.
No system is perfectly secure. So this page sets out what we do, and how to tell us if you find a problem.
1. Your customers’ data stays in your account
Your customers’ information stays in your own account on our client platform. We never copy it into our code repositories.
Each time a workflow runs, it reads only what it needs, works on it in memory, writes the result back to your account and keeps nothing.
The logs from your workflows hold counts and IDs. They never hold names, phone numbers, addresses or message text.
2. Keys and secrets
In the automations we run for you, each step holds only the keys it needs. The step that runs the AI never holds the keys that send messages.
Keys are scoped to one client, and each client’s workflows run in a separate environment.
Secrets for your workflows live only in encrypted secret stores, never in our code or in logs.
3. Messages, consent and opt-out
Every message goes out through your own messaging account, which handles consent and opt-out.
When someone replies STOP, the opt-out is honored before any AI sees the reply.
4. Nothing sends before the go-live test
Nothing goes out to your customers until your workflows pass our go-live test:
- Every workflow is built and run first in a sandbox account, never in your live one.
- Tests go only to test phone numbers and inboxes we control. No real customer is ever a test recipient.
- Every sequence is fired end to end: each template and each branch.
- Opt-out is proven: STOP by text and unsubscribe by email each stop every further message.
- Our AI assistant must correctly refuse, or hand to a person, twenty questions it must not answer. One wrong answer fails the test, and it reruns in full after the fix.
- Carrier registration is approved before any text is sent.
Only then is your live account switched on.
5. Checks on AI replies
Replies our AI drafts in your workflows pass an automatic check before they are written into your account. It checks the length, must-not-answer topics, links that are not on your approved list, and phone numbers or addresses that are not yours.
A reply that fails the check is not sent. It becomes a task for a person.
Our AI assistant says it is an AI.
6. New ads go in paused
New ads go into your ad account paused. Our ad tools cannot switch an ad on, so an ad runs only when a person turns it on in the ad platform.
7. Every approval is on record
Every approval is recorded with the version that was approved. An edit is a new version, and it needs a new approval.
8. Health information
We handle health information only after a business associate agreement is in place.
9. This website
This website is static: no server code, no forms and no logins. Client sign-in happens in our separate client app.
The calculator on our pages runs in your browser; the numbers you enter are not sent to us.
Pages are served over HTTPS with a strict content security policy, and the site’s code and fonts load from our own domain.
10. Reporting a vulnerability
If you think you have found a security problem in our website or services, email support@dijidis.com with the subject “Security”. Tell us what you found and the steps to reproduce it.
We read and reply to every report.
Safe harbor
If you look for and report a problem in good faith, we will not take legal action against you for it. Good faith means you avoid harming people’s privacy, data or our services, you access no more than you need to show the problem, and you give us a reasonable chance to fix it before you share it publicly.
This covers only systems we control. The third-party platforms our services run on have their own rules for security research.