To help you use Dive with confidence, we implement security measures and operations from multiple perspectives to protect your important data.
Compliance with International Information Security Standards
We obtained ISO/IEC 27001:2022 (Information Security Management System: ISMS), an international information security standard, in November 2024. Our organizational structure and service security level have been certified by a third party.

Security Evaluation Platform
We respond to an external security evaluation platform called Assured. Among an overall average score of 76.7, we have received a score of 93.2 points, placing us in the top 25%.
You can also obtain our information via Assured. We encourage you to use this as well.
<What is Assured?>
・It is a third-party evaluation platform for cloud services (https://assured.jp/).
・It is a third-party cloud security evaluation organization that has obtained certification for compliance with the Ministry of Economy, Trade and Industry's "Information Security Service Standards."
・This information is an evaluation of responses to third-party investigations based on international frameworks such as ISO27001 and NIST SP800-53, and major domestic guidelines from the Ministry of Economy, Trade and Industry, Ministry of Internal Affairs and Communications, and FICS.
Security Checklist
We provide a security checklist that complies with the "Cloud Service Level Checklist" released by the Ministry of Economy, Trade and Industry. Use it to verify whether your organization meets your security standards.
Ministry of Economy, Trade and Industry "Cloud Service Level" Checklist (PDF)
Extensive Track Record of Implementation
We are used by many organizations that require strict security, including listed companies and universities.
IHI Group (IHI Transport Machinery), Denso, Kaneka, Nippon Steel Group (Nippon Steel Environmental Energy Solutions), JAL Group (JAL Ground Services), Unitika, SG Holdings (Sagawa Global Logistics), Actio, Sotetsu Holdings (Sotetsu Corporation), National Center for Global Health and Medicine, Tokyo University of Technology, Saga University, and more
Single Sign-On (SSO)
We support Single Sign-On through SAML 2.0 and Microsoft Entra ID (OIDC) integration. IT administrators can centrally manage member accounts, reducing the risk of ID and password leaks and keeping information more secure.
Two-Factor Authentication
Two-Factor Authentication (2FA) is a system where two methods are used to verify your identity when logging in. By adding another authentication method in addition to the normal "password authentication," you enhance the security of your account. Dive supports TOTP (Time-based One-Time Password). To use this feature, you can use common authentication apps such as Google Authenticator and Microsoft Authenticator.
Administrators can also make two-factor authentication mandatory for all users.
Communication and Data Encryption
All communications are encrypted using HTTPS. Third parties cannot eavesdrop on the content. Both databases and files are also encrypted.
Highly Reliable Data Centers
Dive uses Google Cloud Platform (GCP) data centers. GCP has very high reliability, security, and proven performance. Our storage region is domestic (Tokyo).
About GCP Cloud Security
Video Analysis AI Designed Not to Retrain
With typical AI chat services (such as ChatGPT), data entered by users may be used for additional model training.
Dive's video analysis AI runs Google Cloud Vertex AI (Gemini) within a GCP project managed by us, and under Google Cloud's contract terms, your data is not used for AI retraining.
This design allows you to confidently apply AI analysis to highly confidential know-how such as business procedures.
Reliable Data Backup
We back up all data on a timely basis. Even in the event of data loss due to a failure, we have a system in place to restore it.
Access Logs (Audit Logs)
Users with Owner permissions can access logs within the team. Access logs include "login history" and "user and group change history."
<System Logs Collected by the Operations Team>
GCP logs, OS logs, middleware logs, and application logs
Strict Data Management
Server monitoring is 24/7. Access to servers is limited to a limited number of system administrators only. In principle, operations staff do not access your data. (Except when necessary due to customer requests or incident response)
IP Address Restriction
You can configure access permissions from specific IP addresses. You can operate in accordance with your security policies, such as blocking access from outside your office.
Flexible Access Control
You can flexibly configure permissions according to your organization size. You can set access permissions to information on a per-user basis in detail, allowing you to share information more securely.