Trust & Security

Built to earn your dive centre's trust.

Dive shops, PADI instructors and marine-conservation brands ship their entire content strategy through DMS. Here's exactly how we protect that data, your paying students, and your reputation.

Last independently audited: Feb 2026
100% of critical findings resolved
The pillars

Six things every dive centre should ask their tools.

Encrypted in transit and at rest
All traffic runs over TLS 1.2+. Your Dive Brain, vault items and uploads are stored in a MongoDB cluster with disk-level encryption. Nothing lives on a laptop or a spreadsheet.
Payments never touch our servers
All checkouts and card details are handled by Stripe (PCI DSS Level 1). We only receive an anonymised customer id and a subscription state — no card numbers, ever.
Bot & abuse protection
Google reCAPTCHA v3 silently scores every registration and login. Score-based blocking + concurrency-safe credit metering means bots can't burn your account credits.
Strict per-workspace data isolation
Every Dive Brain, vault item, campaign and uploaded file is scoped by user + workspace. There is no admin backdoor into your generated content. Multi-workspace users see only what they've explicitly switched into.
Upload safety & SSRF protection
Uploads are content-sniffed and locked to a strict allowlist (images, PDF, DOCX, TXT). URLs you paste into onboarding are validated against private IP ranges and cloud-metadata endpoints before any request goes out — so a hostile URL can never pivot inside our network.
Session security & auth
Session tokens use cryptographically-random 256-bit values, invalidated on logout. Passwords are bcrypt-hashed with a modern work factor. Email verification links expire in 48 hours and are single-use.
Your data

You own it. You can leave with it.

Portable
Every vault item (reel, carousel, hook, blog, email, product page, campaign) has TXT and DOCX export from the Vault detail page. Your brand voice, your files.
Your team, your call
We don't sell customer lists. We don't share brand data across accounts. Your Dive Brain is never used to train models — it's the input to a stateless API call, nothing more.
Deletion means deletion
Account deletion soft-deletes all workspaces, dive brains, vault items and campaigns immediately. On request we hard-delete within 30 days, in line with GDPR Article 17.
Compliance

Where we stand and what's on the roadmap.

Live
GDPR (EU)
Data-subject rights (access, rectification, erasure, portability) are honoured via written request to hello@divemediastrategist.com within 30 days. Data Processing Addendum available on request for dive-centre accounts.
Live
Stripe PCI DSS Level 1
All payment processing is delegated to Stripe. No cardholder data enters our systems.
On roadmap
SOC 2 Type I
Preparation begins Q4 2026 alongside our first enterprise dive-centre chain contracts.
On roadmap
ISO 27001
Under evaluation. Priority if a customer's parent group requires it.

Found something? Tell us.

We take responsible disclosure seriously. Email details and a proof of concept — we'll acknowledge within 48 hours.

hello@divemediastrategist.com
We use essential cookies to keep you signed in and analytics cookies to improve the platform. Privacy policy.