Skip to content

Trust center

How Dicte Send protects your documents and your recipients

The answers a security questionnaire asks, on one page: where data lives, who can reach it, what recipients see, what we keep and for how long.

At a glance

Hosting
Hosted on dedicated servers in France by a French company, outside the scope of the US CLOUD Act.
Operator
A French company. No foreign entity operates any part of the service.
Subprocessors
None. No third-party AI service, no external analytics processor.
AI processing
On Dicte Send's own dedicated servers; nothing sent to a third party.
Cookies and scripts
One strictly necessary cookie; no third-party script, no tracker.
Languages
All 24 official EU languages, in the application, the reader and the emails.

Account security

Your team's accounts are the first door.

  • Password policy

    Minimum length, required characters and lockout after repeated failures, set by your administrator.

  • Two-factor authentication

    Authenticator app or text message, with recovery codes. Administrators can require it for everyone.

  • Session control

    See every active session and sign out the others; changing your password does it for you.

  • Roles and invitations

    Owner, administrator and member roles per workspace; invitations by email that expire.

  • Verified email addresses

    Every account confirms its address before it can act.

Sharing controls

Every link and every room is a gate you configure.

  • Identity at the gate

    Required email and name, one-time code to verify the address, passcode, allow and block lists by email or domain.

  • NDA before the first page

    Text or PDF, read inline and signed with a typed legal name; signature, time and hashed address kept with the visit.

  • Dynamic watermark

    The recipient's details on every page on screen and burnt into any download you allow.

  • Expiry and revocation

    A date, or one click. A closed link shows nothing.

  • Download control

    Allow downloads or not; choose the original file or a PDF.

Recipient privacy

The people who open your links are protected too.

  • Told upfront

    The gate states that the sender receives reading activity and links to the privacy policy, in the recipient's language.

  • Hashed addresses

    Visitor IP addresses are hashed before storage.

  • Consent kept as proof

    NDA acceptance and cookie choices are recorded with a time and a hashed address.

  • No account, no tracking beyond the visit

    Recipients create nothing and are followed nowhere else.

Operations

What we do, without describing how our infrastructure is built.

  • Backups

    Documents and data are backed up regularly, in France.

  • Retention you control

    Visit records are purged after the period your administrator sets.

  • Audit log

    Administrative, security and AI actions are recorded with identifiers, never content, and can be exported.

  • Erasure

    Users, workspaces and waitlist entries can be deleted or anonymised on request, with an audit entry.

  • Maintenance announced

    Planned maintenance is announced in the application before it starts.

GDPR

The regulation applies in full, and we act on it.

Certifications

Published here when obtained, never before.

  • Roles

    You are the controller of your documents and your recipients' data; Dicte Send is the processor acting on your instructions.

  • Data-subject rights

    Access, rectification, erasure and portability requests are honoured for your team and your recipients.

  • Data-processing agreement

    Available on request, describing the processing, its location and the absence of subprocessors.

  • Records of consent

    Cookie choices and gate acceptances are recorded as proof, with a version so that a policy change asks again.

Coming

Coming

Post-quantum cold encryption

Documents you keep for the long term will be protected at rest with encryption designed to resist the computers of tomorrow, not only today's.

See the roadmap
Coming

Certified electronic signature

Sign inside the flow you already use for NDAs, with a signature that carries legal value across the EU.

See the roadmap

Report a vulnerability or ask a privacy question

Write to us with the details; we acknowledge every report and keep you informed until it is resolved. Please give us a reasonable time to fix an issue before disclosing it.

Have a questionnaire for us?

Send it. We answer in writing, in French or English.