Built to be trusted with the number that matters most.
We handle bank and accounting data for a living, which means security isn’t a feature we bolted on — it’s the reason the read-only architecture exists in the first place.
Read-only by design
Every bank connection is an AISP (Account Information) connection under PSD2 — Dibein can read balances and transactions and cannot move money, initiate a payment, or modify anything in your bank or accounting system.
EU data residency
Application infrastructure and customer data are hosted with EU-based cloud providers, within the EU/EEA. Data does not leave the EU as part of normal operation.
Encryption everywhere
Data is encrypted in transit (TLS 1.2+) and at rest (AES-256). Bank credentials are never seen or stored by Dibein — authentication happens directly between you and your bank through our licensed Open Banking aggregators.
Least-privilege access
Internal access to customer data is role-based, logged, and reviewed quarterly. Engineers do not have standing access to production financial data; access is granted per-incident and expires automatically.
Independent testing
We run an annual third-party penetration test and remediate findings on a tracked timeline. Our first SOC 2 Type II audit is underway, targeting completion in H1 2027.
Responsible disclosure
Found something? Email security@dibein.com — we acknowledge reports within 2 business days and don't take legal action against good-faith security research.
Built for the strictest data protection regime, not retrofitted to it.
Dibein acts as a data processor for the financial data you connect, under a Data Processing Agreement (DPA) available on request. We collect only what’s needed to run forecasts, detect anomalies, and answer your questions — no data is sold, and no customer’s data is used to train models shared across other customers.
Data subject requests (access, correction, deletion) are handled within the statutory 30-day window. If you disconnect a bank or accounting integration, synced data from that source is deleted from active systems within 30 days, with backups aging out on a rolling 90-day cycle.
- Bridge / PowensLicensed Open Banking aggregators (AISP) for bank connectivity
- OVHcloudPrimary application hosting, EU (France) region
- ScalewayBackup infrastructure and object storage, EU (France) region
- PostmarkTransactional email delivery (alerts, digests, receipts)
Need a security questionnaire answered?
We complete vendor security reviews and CAIQ / SIG-lite questionnaires for Scale and Enterprise evaluations — usually within 3 business days.