To help you use Dive with confidence, we implement security measures and operations from various angles to protect your important data.
Compliance with International Information Security Standards
We obtained ISO/IEC 27001 :2022 (Information Security Management System: ISMS), an international standard for information security, in November 2024. A third party has confirmed that our organizational structure and service security level are maintained.

Security Evaluation Platform
We respond to an external security evaluation platform (Assured). Among an overall average score of 76.7 points, we have received a 93.2 point evaluation, which places us in the top 25% overall.
Certification can also be obtained through Assured. We encourage you to take advantage of this option.
<What is Assured (Assured)?>
・It is a third-party evaluation platform for cloud services (https://assured.jp/).
・It is a third-party cloud security evaluation organization certified for compliance with the Ministry of Economy, Trade and Industry's "Information Security Services Standard".
・This information is based on evaluations of third-party survey responses conducted following international frameworks such as ISO27001 and NIST SP800-53, as well as major domestic guidelines from the Ministry of Economy, Trade and Industry, Ministry of Internal Affairs and Communications, and FICS.
Security Checklist
We provide a security checklist that complies with the "Cloud Service Level Checklist" published by the Ministry of Economy, Trade and Industry. Use it to verify whether your company meets your security standards.
Ministry of Economy, Trade and Industry "Cloud Service Level" Checklist (PDF)
Extensive Implementation Track Record
Many companies with strict security requirements, including listed companies and universities, use our service.
IHI Group (IHI Handling Machinery), Denso, Kaneka, Nippon Steel Group (Nippon Steel Environment and Energy Solutions), JAL Group (JAL Ground Service), Unitika, SG Holdings (Sagawa Global Logistics), Actio, Sotetsu Holdings (Sotetsu Corporation), National Center for Global Health and Medicine, Tokyo University of Technology, Saga University, and others
Single Sign-On (SSO)
We support Single Sign-On through SAML2.0 and Microsoft Entra ID (OIDC) integration.
IT administrators can centrally manage member accounts, reducing the risk of ID and password leaks and keeping information more secure.
Two-Factor Authentication
Two-Factor Authentication (2FA) is a mechanism that verifies identity using two methods at login. In addition to normal password-based authentication, performing another authentication method enhances account security. Dive supports TOTP (Time-based One-Time Password). To use this feature, you use general authentication apps such as Google Authenticator and Microsoft Authenticator.
Administrators can also configure two-factor authentication to be required for all users.
Communication and Data Encryption
All communications are encrypted using HTTPS.
Third parties cannot eavesdrop on the content.
Both databases and files are also encrypted.
Reliable Data Centers
Dive uses data centers from Google Cloud Platform (GCP). GCP has very high reliability, security, and proven track record. The storage region is domestic (Tokyo). For video and image delivery, Google's edge may be used to enhance playback stability, and content may be temporarily cached at the edge in the region where it is viewed. The storage location remains in the Tokyo region.
GCP Cloud Security
Video Analysis AI is designed not to retrain
With general AI chat services (such as ChatGPT), data entered by users may be used for additional training of the model.
Dive's video analysis AI runs Google Cloud Vertex AI (Gemini) within our GCP project, and we have adopted a system that ensures your data is not used for AI retraining in accordance with Google Cloud contracts.
This is a design that allows you to safely apply AI analysis to highly confidential operational procedures.
Reliable Data Backup
All data is backed up regularly. We have measures in place to restore data even in the event of data loss due to system failures or other issues.
Access Logs (Audit Logs)
Users with Owner permission can obtain access logs within a team.
Access logs include "login history" and "user and group change history".
GCP logs, OS logs, middleware logs, application logs
Strict Data Management
Server monitoring is 24/7. Access to servers is restricted to limited system operations personnel only. In addition, operations staff do not access customer data as a rule. (Except in cases where necessary due to customer requests or incident response)
IP Address Restriction
You can configure access permissions from specific IP addresses. You can operate in accordance with your security policy, such as blocking access from outside your company office.
Flexible Access Control
Flexible permission settings are possible depending on your organization size. You can set fine-grained permissions for accessing information by user, allowing for more secure information sharing.