Dify
English
English
  • Getting Started
    • Welcome to Dify
      • Features and Specifications
      • List of Model Providers
    • Dify Community
      • Deploy with Docker Compose
      • Start with Local Source Code
      • Deploy with aaPanel
      • Start Frontend Docker Container Separately
      • Environment Variables Explanation
      • FAQs
    • Dify Cloud
    • Dify Premium on AWS
    • Dify for Education
  • Guides
    • Model
      • Add New Provider
      • Predefined Model Integration
      • Custom Model Integration
      • Interfaces
      • Schema
      • Load Balancing
    • Application Orchestration
      • Create Application
      • Chatbot Application
        • Multiple Model Debugging
      • Agent
      • Application Toolkits
        • Moderation Tool
    • Workflow
      • Key Concepts
      • Variables
      • Node Description
        • Start
        • End
        • Answer
        • LLM
        • Knowledge Retrieval
        • Question Classifier
        • Conditional Branch IF/ELSE
        • Code Execution
        • Template
        • Doc Extractor
        • List Operator
        • Variable Aggregator
        • Variable Assigner
        • Iteration
        • Parameter Extraction
        • HTTP Request
        • Agent
        • Tools
        • Loop
      • Shortcut Key
      • Orchestrate Node
      • File Upload
      • Error Handling
        • Predefined Error Handling Logic
        • Error Type
      • Additional Features
      • Debug and Preview
        • Preview and Run
        • Step Run
        • Conversation/Run Logs
        • Checklist
        • Run History
      • Application Publishing
      • Structured Outputs
      • Bulletin: Image Upload Replaced by File Upload
    • Knowledge
      • Create Knowledge
        • 1. Import Text Data
          • 1.1 Import Data from Notion
          • 1.2 Import Data from Website
        • 2. Choose a Chunk Mode
        • 3. Select the Indexing Method and Retrieval Setting
      • Manage Knowledge
        • Maintain Documents
        • Maintain Knowledge via API
      • Metadata
      • Integrate Knowledge Base within Application
      • Retrieval Test / Citation and Attributions
      • Knowledge Request Rate Limit
      • Connect to an External Knowledge Base
      • External Knowledge API
    • Tools
      • Quick Tool Integration
      • Advanced Tool Integration
      • Tool Configuration
        • Google
        • Bing
        • SearchApi
        • StableDiffusion
        • Dall-e
        • Perplexity Search
        • AlphaVantage
        • Youtube
        • SearXNG
        • Serper
        • SiliconFlow (Flux AI Supported)
        • ComfyUI
    • Publishing
      • Publish as a Single-page Web App
        • Web App Settings
        • Text Generator Application
        • Conversation Application
      • Embedding In Websites
      • Developing with APIs
      • Re-develop Based on Frontend Templates
    • Annotation
      • Logs and Annotation
      • Annotation Reply
    • Monitoring
      • Data Analysis
      • Integrate External Ops Tools
        • Integrate LangSmith
        • Integrate Langfuse
        • Integrate Opik
    • Extension
      • API-Based Extension
        • External Data Tool
        • Deploy API Tools with Cloudflare Workers
        • Moderation
      • Code-Based Extension
        • External Data Tool
        • Moderation
    • Collaboration
      • Discover
      • Invite and Manage Members
    • Management
      • App Management
      • Team Members Management
      • Personal Account Management
      • Subscription Management
      • Version Control
  • Workshop
    • Basic
      • How to Build an AI Image Generation App
    • Intermediate
      • Build An Article Reader Using File Upload
      • Building a Smart Customer Service Bot Using a Knowledge Base
      • Generating analysis of Twitter account using Chatflow Agent
  • Community
    • Seek Support
    • Become a Contributor
    • Contributing to Dify Documentation
  • Plugins
    • Introduction
    • Quick Start
      • Install and Use Plugins
      • Develop Plugins
        • Initialize Development Tools
        • Tool Plugin
        • Model Plugin
          • Create Model Providers
          • Integrate the Predefined Model
          • Integrate the Customizable Model
        • Agent Strategy Plugin
        • Extension Plugin
        • Bundle
      • Debug Plugin
    • Manage Plugins
    • Schema Specification
      • Manifest
      • Endpoint
      • Tool
      • Agent
      • Model
        • Model Designing Rules
        • Model Schema
      • General Specifications
      • Persistent Storage
      • Reverse Invocation of the Dify Service
        • App
        • Model
        • Tool
        • Node
    • Best Practice
      • Develop a Slack Bot Plugin
      • Dify MCP Plugin Guide: Connect Zapier and Automate Email Delivery with Ease
    • Publish Plugins
      • Publish Plugins Automatically
      • Publish to Dify Marketplace
        • Plugin Developer Guidelines
        • Plugin Privacy Protection Guidelines
      • Publish to Your Personal GitHub Repository
      • Package the Plugin File and Publish it
      • Signing Plugins for Third-Party Signature Verification
    • FAQ
  • Development
    • Backend
      • DifySandbox
        • Contribution Guide
    • Models Integration
      • Integrate Open Source Models from Hugging Face
      • Integrate Open Source Models from Replicate
      • Integrate Local Models Deployed by Xinference
      • Integrate Local Models Deployed by OpenLLM
      • Integrate Local Models Deployed by LocalAI
      • Integrate Local Models Deployed by Ollama
      • Integrate Models on LiteLLM Proxy
      • Integrating with GPUStack for Local Model Deployment
      • Integrating AWS Bedrock Models (DeepSeek)
    • Migration
      • Migrating Community Edition to v1.0.0
  • Learn More
    • Use Cases
      • DeepSeek & Dify Integration Guide: Building AI Applications with Multi-Turn Reasoning
      • Private Deployment of Ollama + DeepSeek + Dify: Build Your Own AI Assistant
      • Build a Notion AI Assistant
      • Create a MidJourney Prompt Bot with Dify
      • Create an AI Chatbot with Business Data in Minutes
      • Integrating Dify Chatbot into Your Wix Website
      • How to connect with AWS Bedrock Knowledge Base?
      • Building the Dify Scheduler
      • Building an AI Thesis Slack Bot on Dify
    • Extended Reading
      • What is LLMOps?
      • Retrieval-Augmented Generation (RAG)
        • Hybrid Search
        • Re-ranking
        • Retrieval Modes
      • How to Use JSON Schema Output in Dify?
    • FAQ
      • Self-Host
      • LLM Configuration and Usage
      • Plugins
  • Policies
    • Open Source License
    • User Agreement
      • Terms of Service
      • Privacy Policy
      • Get Compliance Report
  • Features
    • Workflow
Powered by GitBook
On this page
  1. Policies
  2. User Agreement

Get Compliance Report

Author: Yongle, Allen

PreviousUser AgreementNextWorkflow

Last updated 4 months ago

From the moment Dify.AI launched its product, it received inquiries from individual developers and enterprise users worldwide regarding whether Dify.AI meets information security and data privacy compliance requirements. Consequently, the team has strictly followed industry standards from the design phase onward, gradually establishing a comprehensive information security and data privacy compliance management system.

Dify.AI has officially obtained SOC 2 Type I, SOC 2 Type II, ISO 27001:2022, and GDPR certifications, demonstrating that the product has reached internationally leading standards in data security, privacy protection, and compliance. This milestone further underscores Dify.AI's unwavering commitment to user data security.

If you are using Dify’s cloud version as part of your vendor security evaluation, click the top-right corner of the page, select Compliance, and download the necessary reports to review Dify's compliance and certification documents.

For Enterprise customers, if you want to check the compliance certificates and reports, please contact your account representative to initiate the appropriate business process.

Compliance Reports Availability

Different team tiers have access to the following compliance certifications:

Certification Type
Free / Sandbox
Professional
Enterprise

SOC 2 Type I Report

-

✅

✅

SOC 2 Type II Report

-

-

✅

ISO 27001:2022 Certificate

-

-

✅

GDPR Data Protection Agreement

✅

✅

✅

For access to higher-level compliance certifications, please upgrade your team on the page.

The following explains how to obtain various compliance certification reports.

SOC 2 Type I Report

A SOC 2 Type I report is a third-party audit report that evaluates and confirms the design and implementation of an organization's security controls at a specific point in time. SOC 2, which stands for System and Organization Controls 2, is a set of criteria for managing and protecting data based on five trust service principles: Security, Availability, Processing Integrity, Confidentiality, and Privacy. The Type I report specifically assesses whether an organization has appropriate controls in place to meet the relevant criteria at the time of the audit.

Only team owners can download Dify's SOC 2 Type I report via Top-right → Compliance.

SOC 2 Type I Report

SOC 2 Type II Report

A SOC 2 Type II report is a third-party audit report that evaluates and confirms the design and implementation of an organization's security controls over a specified period. SOC 2, which stands for System and Organization Controls 2, is a set of criteria for managing and protecting data based on five trust service principles: Security, Availability, Processing Integrity, Confidentiality, and Privacy. The Type II report provides detailed insights into how well an organization’s security controls work over time, giving stakeholders confidence that the organization consistently adheres to industry standards for managing sensitive data.

Only team owners can download Dify's SOC 2 Type I report via Top-right → Compliance.

ISO 27001: 2022 Certificate

The ISO 27001:2022 certificate is an internationally recognized standard for information security management systems (ISMS). It is part of the ISO/IEC 27000 family of standards, which focuses on protecting sensitive information through a comprehensive set of security controls. The ISO 27001:2022 standard is designed to help organizations establish, implement, maintain, and continually improve their information security management system. The 2022 version of the standard reflects the latest updates and best practices in information security, aligning with current security challenges and technological advancements. It provides a systematic approach to managing sensitive company information, ensuring its confidentiality, integrity, and availability through the implementation of risk management and security controls.

GDPR Data Protection Agreement

A Data Protection Agreement (DPA) is a legally binding contract between a data controller and a data processor under the General Data Protection Regulation (GDPR). The GDPR, which came into effect in May 2018, sets out the legal framework for data protection within the European Union (EU), and applies to organizations that process personal data of EU residents. A DPA is required when a data controller engages a third-party processor to handle personal data, ensuring that both parties are in compliance with GDPR obligations and safeguarding the rights of individuals whose data is being processed.

Everyone can Download Dify's DPA in our official website.

SOC 2 Type II Report
ISO 27001: 2022 Certificate
DPA
Pricing