Secure & Comply
This is the technical counterpart to a security or compliance claim. These pages describe mechanism — what data flows where, what persists, what is recorded, and what an administrator can erase — so you can draw your own conclusions and map them to the obligations you carry, rather than take an assurance on faith.
Start with the model DioscHub is built for, then follow the data.
Threat model Self-hosted and single-tenant: the trust boundaries DioscHub assumes, what it defends in-band, and what you secure around it.
Data handling: what flows where A map of the data DioscHub moves and keeps — from bind, to the transport, to the stores that back a conversation.
The credential-blind guarantee The user's auth never enters the model's context, the browser trace, or the approval record. Here is how that holds.
Privacy boundary: chat data vs. knowledge A user's private chat uploads and shared knowledge-base documents live in separate stores with different rules.
Licensing & tiers What Free, Pro, and Enterprise each include, and the non-removable 'Powered by DioscHub' attribution on Free.
AI disclosure Where AI-interaction disclosure sits — the greeting is the control you use to tell users they are talking to an AI.
Audit trail The reviewable admin and erasure trails you can query, and the append-only approval log written as each decision is made.
Data erasure & GDPR Administrator-driven subject-access search and erasure on every tier — the exact scope removed, and what is retained by design.
Administrator roles & permissions Who may operate the deployment — deny-by-default roles, tier-capped permissions, and scoped, revocable admin API keys.