🎉 AI Scheduling is live!Try free
Security & Compliance

Enterprise-grade securityout of the box

We take security seriously so you don't have to. SOC 2, HIPAA, GDPR — fully covered from day one.

SOC 2 Type IIHIPAA compliantGDPR ready
Security Status
All systems secure
Active
Encryption at restAES-256
Encryption in transitTLS 1.3
Two-factor authEnforced
Audit logging24/7
Uptime SLA99.9%
6
Certifications
AES-256
Encryption
99.9%
Uptime SLA
24/7
Monitoring
Architecture

Four layers of protection

Defense in depth — every layer independently secured.

Application Layer
WAF, rate limiting, DDoS protection
Identity Layer
SSO, 2FA, OAuth 2.0, session management
Data Layer
AES-256 at rest, TLS 1.3 in transit
Infrastructure
SOC 2 data centers, 99.9% uptime

Certifications & compliance

Independently verified. Continuously audited.

SOC 2 Type II
Independently audited annually by a third-party firm.
HIPAA Compliant
Safe for healthcare teams and patient scheduling.
GDPR Ready
Full compliance for teams operating in the EU.
ISO 27001
International standard for information security.
PCI DSS
Payment data handled to the highest standard.
99.9% Uptime SLA
Enterprise-grade reliability guaranteed.

Built secure from the ground up

Six layers of protection that keep your data and your guests' data safe.

Encryption everywhere

All data encrypted at rest (AES-256) and in transit (TLS 1.3). Your calendar data never travels unprotected.

SSO & SAML

Enterprise single sign-on with support for Okta, Azure AD, Google Workspace, and any SAML 2.0 provider.

Audit logs

Every login, change, and booking event is logged with full timestamps. Export for compliance audits instantly.

Data residency

Choose where your data lives. US, EU, or APAC data centers available on Enterprise plans.

2FA enforcement

Require two-factor authentication for all users in your organization — no exceptions.

SCIM provisioning

Auto-provision and de-provision users via SCIM. No manual account management.

Security

Our commitment to you

  • We never sell your data to third parties
  • Your booking data is yours — export anytime
  • Penetration tested by independent researchers
  • Bug bounty program with public disclosure policy
  • Transparent incident communication within 1 hour
Trusted by security teams

Security teams trust Diurnly

"The security audit passed on the first try. SOC 2, HIPAA, SSO — everything was ready out of the box."

LM
Lena M.
COO, Vercel

"Our security team reviewed Diurnly and approved it in days, not months. The documentation is impeccable."

OF
Omar F.
CTO, Scale AI

"Enterprise-grade security without the enterprise-grade headache. SSO just works."

AR
Aisha R.
Founder, Linear
Compliance timeline

Our security journey

Continuous investment in security and compliance.

2024 Q1

SOC 2 Type II certified

Completed independent audit with zero findings.

2024 Q2

HIPAA compliance

Signed first Business Associate Agreements with healthcare customers.

2024 Q3

GDPR readiness

Full EU data protection compliance with data residency options.

2024 Q4

ISO 27001 certified

International information security management standard achieved.

2025 Q1

PCI DSS compliance

Payment processing certified to the highest industry standard.

2025 Q2

99.9% uptime SLA

Enterprise-grade reliability guarantee with service credits.

FAQ

Questions, answered

Yes. Diurnly is SOC 2 Type II certified and audited annually by an independent third-party firm. Our latest report is available under NDA.

Security questions? Talk to us.

Our security team is available for enterprise reviews and custom compliance discussions.