To ensure you can use Dive with confidence, we implement Security measures and operations from various angles to protect your valuable data.
Compliance with International Information Security Standards
We obtained ISO/IEC 27001:2022 (Information Security Management System: ISMS), the international standard for information security, in November 2024. A third party has verified that our organizational structure and service Security Level are maintained.

Security Evaluation Platform
We respond to an external security evaluation platform (Assured). Among an overall average of 76.7 points, we received a rating of 93.2 points, which places us in the top 25% overall.
We can also be evaluated via Assured. Please take advantage of this option as well.
<What is Assured?>
· It is a third-party evaluation platform for cloud services (https://assured.jp/).
· It is a third-party cloud security evaluation agency that has received compliance certification with the Ministry of Economy, Trade and Industry's "Information Security Service Standards."
· The information is based on third-party survey responses conducted under international frameworks such as ISO27001 and NIST SP800-53, and major domestic guidelines such as those from the Ministry of Economy, Trade and Industry, Ministry of Internal Affairs and Communications, and FICS.
Security Checklist
We provide a Security Checklist that complies with the "Cloud Service Level Checklist" published by the Ministry of Economy, Trade and Industry. Use it to Confirm whether your company's security standards are met.
Ministry of Economy, Trade and Industry "Cloud Service Level" Checklist (PDF)
Extensive Adoption Track Record
We are used by many listed companies, universities, and other organizations with strict Security requirements.
IHI Group (IHI Transport Machinery), Denso, Kaneka, Nippon Steel Group (Nippon Steel Environment and Energy Solutions), JAL Group (JAL Ground Services), Unitika, SG Holdings (Sagawa Global Logistics), Actio, Sotetsu Holdings (Sotetsu Enterprise), National Center for Global Health and Medicine, Tokyo University of Technology, Saga University, and others
Single Sign-On (SSO)
We support Single Sign-On (SSO) via SAML 2.0 and Microsoft Entra ID (OIDC) Integration. IT administrators can centrally Manage Member accounts, reducing the risk of ID and Password leaks and helping keep information safer.
Two-Factor Authentication
Two-Factor Authentication (2FA) is a mechanism that verifies identity using two methods when logging in. In addition to the usual "authentication by Password," an additional authentication is performed to enhance account Safety. Dive supports TOTP (Time-based One-Time Password). This Feature uses common authentication apps such as Google Authenticator or Microsoft Authenticator.
Administrators can also require two-factor authentication for all Users.
Communication and Data Encryption
All communications are encrypted with HTTPS. Third parties cannot eavesdrop on content. Additionally, both databases and Files are encrypted.
Reliable Data Centers
Dive uses Google Cloud Platform (GCP) data centers. GCP has extremely high reliability, Security, and track record. Our Storage region is domestic (Tokyo).
GCP Cloud Security Overview
Video Analysis AI is Designed Not to Retrain
In general AI Chat services (such as ChatGPT), user-input data may be used for additional model training.
Dive's video analysis AI runs Google Cloud Vertex AI (Gemini) within a GCP project managed by us, and we have adopted a mechanism based on Google Cloud contracts to ensure that your data is not used for AI retraining.
This is a design that allows you to confidently apply confidential know-how of business procedures to AI analysis.
Reliable Data Backup
All data is backed up in a timely manner. Even if data loss occurs due to a failure, we have systems in place to Restore it.
Access Logs (Audit log)
Users with Owner Permission can obtain access Logs within the Team. Access Logs include "Log in History" and "User and Group Change history." <System Logs obtained by our operations>
GCP Logs, OS Logs, middleware logs, application logs
Strict Data Management
Server monitoring is 24 hours, 365 days. Server access is limited to only designated System operations staff. Additionally, operations staff do not access customer data in principle. (except in cases where the customer requests it or for unavoidable reasons such as failure response)
IP address restriction
You can Set permissions for access From specific IP addresses. You can operate in accordance with your security policy, such as blocking access From outside your company office
Flexible Access Control
You can set flexible Permission settings depending on your organization's size. You can finely set Permission for each User to access information, allowing you to Share information more securely.