Trust
Security
How Diagramy protects customer data, controls access, and keeps architecture workspaces secure.
Last updated July 24, 2026
Our approach
Architecture models often describe systems that matter. Diagramy is built so teams can collaborate on that work with clear access controls, an auditable history, and encryption in transit and at rest.
For privacy details, see our Privacy Policy. To report a vulnerability or security concern, email [email protected].
Encryption
- TLS for data in transit between clients and our services
- Encryption at rest for primary datastores
- Secrets and credentials managed outside application source code
Access control
- Authenticated accounts with secure session handling
- Workspace-scoped membership and role-based permissions
- Private architectures visible only to workspace members
- Optional share links and embeds that can be revoked
Product governance controls
On Team plans, Diagramy adds workflow controls that reduce accidental or unreviewed change to critical architecture:
- Protected main branches for architecture repositories
- Required reviews and approvals before merge
- Ownership rules so services have clear owners
- Audit history of changes, comments, and merges
- Version history with compare and restore
Infrastructure and operations
- Hosted on reputable cloud infrastructure with network isolation
- Least-privilege access for production systems
- Monitoring and logging for availability and abuse detection
- Backups of customer data with controlled restore procedures
Responsible disclosure
If you believe you have found a security issue, please email [email protected] with enough detail for us to reproduce it. We ask that you give us a reasonable window to investigate and remediate before any public disclosure.
Questions
Security and trust inquiries: [email protected]
Privacy inquiries: [email protected]