How Dembri protects your data.
Dembri handles compliance documents and personal data, so security is foundational, not an afterthought. This page summarises our controls and how to report an issue — the full governance posture lives in the Trust Center.
Encryption
All traffic is served over TLS. Documents and data are encrypted at rest by the underlying infrastructure (Supabase / Vercel).
Tenant isolation
Every row is scoped to its owner with Postgres row-level security. Firm members only see clients within their assigned scope.
Immutable audit log
Sensitive actions are recorded to an append-only audit log. On account deletion, log rows are anonymised, not erased, to preserve compliance integrity.
Data protection
Aligned with UAE PDPL (Federal Decree-Law No. 45 of 2021) and DIFC Data Protection Law No. 5 of 2020. Uploaded audit files are deleted after 7 days.
Responsible disclosure
Found a vulnerability? Email privacy@dembri.com with the details and steps to reproduce. We'll acknowledge your report, keep you updated, and credit you if you'd like once it's resolved. Please give us reasonable time to fix an issue before disclosing it publicly, and don't access or modify data that isn't yours.
Full Trust Center