# Security and responsible disclosure.

> How Dienox protects the knowledge of the organisations that use it, and how to report a vulnerability.

Source: https://dienox.com/security  
Last updated: 2026-09-24

Last updated 24 September 2026 · Dienox B.V.

## Our approach

An organisation trusts Dienox with how it works, and trusts the agents on it to act within limits. So security is designed in, not added on: what an agent may not do does not exist for it, every change can be traced and undone, and one organisation’s knowledge never reaches another.

## Organisations kept apart

- Every organisation has its own knowledge base, kept separately from every other.
- Every request is resolved to exactly one organisation, and every query is scoped to it.
- A connection from an AI tool belongs to one organisation. It cannot see or reach another, whoever asks.

## Permissions and approvals

- Every action on every connection is read, write or irreversible, and switched on or off per agent.
- An action that is off is not in the agent’s toolbox, so it cannot be called, however the agent is asked.
- Irreversible actions wait for a person with the right role, and an approval counts once.
- People have roles per organisation: administrator, editor or reader.

## Accounts and access

- Passwords are stored only as secure hashes, and login attempts are rate-limited.
- AI tools connect through OAuth: access tokens last hours, not months, and can be revoked at any time.
- Sensitive changes, such as managing members or issuing tokens, ask for your password again.
- Dienox staff reach the admin console only with a fresh password confirmation, and what they change there is logged.

## Infrastructure

- Hosted in the Netherlands, with daily backups.
- All traffic is encrypted in transit, and the site sits behind Cloudflare’s protection against attacks.
- Strict security headers on every page, including a content security policy and no framing by other sites.
- Limits on every machine-facing interface, so a runaway AI tool meets a clear error instead of a flood.
- Dependencies are kept current, and the platform is reviewed for security as it grows.

## A trail of everything

What was read and what was changed, by which person or agent, for whom and at what cost. Every change to a knowledge base is kept in its history and can be undone. Your knowledge is kept in open formats, so you can take all of it with you at any time.

## In your own environment

The Enterprise edition runs the same platform on your own server, in your Azure or your AWS, with a local model where nothing may leave. Your knowledge, your data and your access then never leave your environment. [Join the beta](https://dienox.com/beta?edition=enterprise) to talk about it.

## Responsible disclosure

Found a vulnerability? We want to hear about it, and we will work with you to fix it. Mail [security@dienox.com](mailto:security@dienox.com) with what you found, how to reproduce it and what you think the impact is. Our machine-readable contact is at [/.well-known/security.txt](https://dienox.com/.well-known/security.txt).

### We ask you to

- report it as soon as possible, and give us reasonable time to fix it before telling anyone else;
- not access, change or delete more data than needed to show the problem, and never data of others;
- not disrupt the service: no denial of service, spam or social engineering of our staff or customers;
- not use physical attacks, or attacks on the systems of our providers.

### We promise to

- reply within three working days, and keep you informed while we fix it;
- not take legal action against you for research that follows these rules in good faith;
- handle your report confidentially, and not share your details without your permission;
- name you as the finder once it is fixed, if you would like that.

### Out of scope

- findings without a demonstrable security impact, such as missing best-practice headers on a static file;
- reports from automated scanners without a working proof;
- vulnerabilities in the AI tools you connect, which belong with their own providers;
- rate limits on the public beta form, and the absence of a lockout after failed logins.
