Dibein
Security & trust

Built to be trusted with the number that matters most.

We handle bank and accounting data for a living, which means security isn’t a feature we bolted on — it’s the reason the read-only architecture exists in the first place.

Read-only by design

Every bank connection is an AISP (Account Information) connection under PSD2 — Dibein can read balances and transactions and cannot move money, initiate a payment, or modify anything in your bank or accounting system.

EU data residency

Application infrastructure and customer data are hosted with EU-based cloud providers, within the EU/EEA. Data does not leave the EU as part of normal operation.

Encryption everywhere

Data is encrypted in transit (TLS 1.2+) and at rest (AES-256). Bank credentials are never seen or stored by Dibein — authentication happens directly between you and your bank through our licensed Open Banking aggregators.

Least-privilege access

Internal access to customer data is role-based, logged, and reviewed quarterly. Engineers do not have standing access to production financial data; access is granted per-incident and expires automatically.

Independent testing

We run an annual third-party penetration test and remediate findings on a tracked timeline. Our first SOC 2 Type II audit is underway, targeting completion in H1 2027.

Responsible disclosure

Found something? Email security@dibein.com — we acknowledge reports within 2 business days and don't take legal action against good-faith security research.

GDPR

Built for the strictest data protection regime, not retrofitted to it.

Dibein acts as a data processor for the financial data you connect, under a Data Processing Agreement (DPA) available on request. We collect only what’s needed to run forecasts, detect anomalies, and answer your questions — no data is sold, and no customer’s data is used to train models shared across other customers.

Data subject requests (access, correction, deletion) are handled within the statutory 30-day window. If you disconnect a bank or accounting integration, synced data from that source is deleted from active systems within 30 days, with backups aging out on a rolling 90-day cycle.

Sub-processors
  • Bridge / PowensLicensed Open Banking aggregators (AISP) for bank connectivity
  • OVHcloudPrimary application hosting, EU (France) region
  • ScalewayBackup infrastructure and object storage, EU (France) region
  • PostmarkTransactional email delivery (alerts, digests, receipts)

Need a security questionnaire answered?

We complete vendor security reviews and CAIQ / SIG-lite questionnaires for Scale and Enterprise evaluations — usually within 3 business days.

Request our security pack