"Build Production-Ready AI Agents."
Dify is a platform for AI agents, RAG, visual workflows, chatbots, and no-code AI applications. Teams can develop, test, deploy, monitor, and integrate LLM apps into existing systems via APIs or plugins.
Dify
Build Production-Ready AI Agent.
Location: USA ⓘ LangGenius, Inc., 548 Market St, PMB 60083, San Francisco, CA 94104-5401, USA.
Community Edition Open-source self-hosting with agents, workflows, RAG, APIs, and plugins. Subscription Professional Cloud workspace with extended usage scope, higher storage, logs, and team features.
Team Larger team workspace with more users, capacities, and advanced features.
Enterprise Customized infrastructure, security, support, and governance solution. Other Dify Premium on AWS One-click deployment as an AWS AMI in your own VPC with branding and enterprise options.
Your own model providers Direct connection of your own API keys for OpenAI, Anthropic, Google, local models, and additional providers.
Target audience
Dify is aimed at developers, business departments, AI agencies, product teams, start-ups, and companies that want to create their own AI assistants, RAG applications, or workflow automations without full in-house development.
Outstanding features
Dify combines no-code workflows, agents, RAG, data sources, plugins, tool calls, and API deployment. Particularly relevant is the Knowledge Pipeline for controllable document processing and context engineering.
Main application areas
Typical scenarios include internal knowledge bots, customer service assistants, document AI, process automation, text and data agents, lead qualification, research, and no-code AI apps.
Usage & notes
Dify should be introduced with clear model specifications, role permissions, data sources, plugin reviews, and test sets. In the cloud, no sensitive data should be processed unless this is explicitly secured contractually and technically.
| Target audience | Assessment |
|---|---|
| Private individuals | Conditionally – good for experiments, but more technically demanding than traditional AI chat tools. |
| Self-employed / Freelancers | Very well suited – for custom chatbots, customer portals, RAG apps, and automations. |
| SMEs | Yes – suitable for internal AI assistants, knowledge bases, and workflow automation. |
| Large enterprises | Yes, with Enterprise or self-hosting – for governance, own infrastructure, and scaled agents. |
| Developers / AI teams | Very well suited – core target group for APIs, plugins, workflows, and model integration. |
| Education / Universities | Yes – Community Edition can be self-hosted for free. |
| Privacy-sensitive organizations | Good with self-hosting, conditional with Dify Cloud – cloud data may be processed internationally. |
Hosting & Data
1) On-prem / local hosting
Meaning: The company operates the solution on its own hardware or within its own infrastructure. In the strictest sense, not only the application runs locally, but ideally the model as well.
2) Private cloud / data center
Meaning: The solution runs in a dedicated or more clearly separated cloud environment, often with a hosting provider or hyperscaler, but in a German data center or in a particularly controlled environment.
3) EU SaaS / managed
Meaning: The provider operates the solution itself as a service. The company uses the tool as a ready-made cloud service, ideally with EU data residency.
4) Hybrid
Meaning: One part of the processing remains internal / local / in a private cloud, while another part runs in an external cloud or EU SaaS.
5) AVV / DPA
Meaning: This is the data processing agreement or Data Processing Addendum. It governs that the provider processes personal data on behalf of the customer and is bound by the customer's instructions.
6) No training
Meaning: The provider does not use your prompts, uploads, attachments, chat histories, or outputs for training or improving the general model — ideally excluded by contract.
7) Open-source / transparency path
Meaning: There is a path toward greater technical transparency and sovereignty, for example through:
- open models
- documented components
- self-hostable parts
- traceable architecture
- export / switching options
| On-prem / local hosting | ✅ |
| Private cloud / data center | ✅ |
| EU SaaS / Managed | ⚠️ |
| Hybrid | ⚠️ |
| DPA / AVV | ✅ |
| No training on customer data | ❓ |
| Open source / transparency path | ✅ |
On-Prem / local hosting: covered
The website mentions self-hosted and describes enterprise deployment options as 'on-premise, public cloud, VPC'. This clearly documents a local or customer-controlled operating model.
Private cloud / data center: covered
The enterprise page lists 'public cloud' and 'VPC' as deployment options. This documents a distinct private-cloud / controlled infrastructure path for customers.
EU SaaS / managed: partial
A dedicated cloud service clearly exists. However, the privacy policy does not mention guaranteed EU data residency for the SaaS; instead, it names the USA, EEA, and China as possible processing locations, and website servers in the USA.
Hybrid: partial
An explicit hybrid offering is not clearly described. Due to the documented combinability of on-premise/public cloud/VPC and external cloud, a hybrid deployment is indirectly plausible, but not specifically defined on the website.
DPA / DPA: covered
The website refers multiple times to a 'Data Protection Agreement', and the compliance article mentions comprehensive data processing agreements as part of GDPR compliance.
No training: unclear
A clear statement that prompts, uploads, chats, or outputs are not used for training general models, or an explicit opt-out option for AI training, is not provided on the website.
Open source / transparency path: covered
Dify describes itself as fully open source and mentions a mixed AGPL+MIT licensing model. In addition, self-hosting and open components such as DifySandbox are documented, which provides a clear transparency / sovereignty path.
Data processing
For EU/EEA users, the main distinction is between SaaS and self/customer-controlled operation. The website shows that the standard SaaS does not provide pure EU data residency; according to the privacy policy, data may be processed or stored in the USA, EEA, and China, and the website servers are located in the USA. At the same time, Dify names reliable alternatives for enterprise and self-hosted use, such as on-premise, public cloud, and VPC. This makes more privacy-friendly EU/EEA usage possible if customers control the deployment themselves within EU/EEA infrastructure.
Conclusion
For a European directory, Dify is best categorized as GDPR-compliant for use via self-hosting/on-premise or controlled enterprise deployments. The website provides sufficient indications for this. By contrast, the standard SaaS is weaker from a data protection perspective because no clear EU data residency is guaranteed and US/third-country processing is explicitly mentioned.
Sources
- https://dify.ai/privacy
- https://dify.ai/pricing
- https://dify.ai/blog/dify-achieves-soc-2-iso-27001-gdpr-compliance-for-the-second-year-running
- https://dify.ai/blog/dify-open-source
- https://dify.ai/blog/openai-assistants-api-vs-dify-self-hosting-flexible-ai-solutions
- https://dify.ai/blog/dify-x-microsoft-azure-marketplace
- https://dify.ai/jp/enterprise
| On-prem / local hosting | ✅ |
| Private cloud / data center | ✅ |
| EU SaaS / Managed | ⚠️ |
| Hybrid | ⚠️ |
| DPA / AVV | ✅ |
| No training on customer data | ❓ |
| Open source / transparency path | ✅ |
On-Prem / local hosting: covered
The website mentions self-hosted and describes enterprise deployment options as 'on-premise, public cloud, VPC'. This clearly documents a local or customer-controlled operating model.
Private cloud / data center: covered
The enterprise page lists 'public cloud' and 'VPC' as deployment options. This documents a distinct private-cloud / controlled infrastructure path for customers.
EU SaaS / managed: partial
A dedicated cloud service clearly exists. However, the privacy policy does not mention guaranteed EU data residency for the SaaS; instead, it names the USA, EEA, and China as possible processing locations, and website servers in the USA.
Hybrid: partial
An explicit hybrid offering is not clearly described. Due to the documented combinability of on-premise/public cloud/VPC and external cloud, a hybrid deployment is indirectly plausible, but not specifically defined on the website.
DPA / DPA: covered
The website refers multiple times to a 'Data Protection Agreement', and the compliance article mentions comprehensive data processing agreements as part of GDPR compliance.
No training: unclear
A clear statement that prompts, uploads, chats, or outputs are not used for training general models, or an explicit opt-out option for AI training, is not provided on the website.
Open source / transparency path: covered
Dify describes itself as fully open source and mentions a mixed AGPL+MIT licensing model. In addition, self-hosting and open components such as DifySandbox are documented, which provides a clear transparency / sovereignty path.
Data processing
For EU/EEA users, the main distinction is between SaaS and self/customer-controlled operation. The website shows that the standard SaaS does not provide pure EU data residency; according to the privacy policy, data may be processed or stored in the USA, EEA, and China, and the website servers are located in the USA. At the same time, Dify names reliable alternatives for enterprise and self-hosted use, such as on-premise, public cloud, and VPC. This makes more privacy-friendly EU/EEA usage possible if customers control the deployment themselves within EU/EEA infrastructure.
Conclusion
For a European directory, Dify is best categorized as GDPR-compliant for use via self-hosting/on-premise or controlled enterprise deployments. The website provides sufficient indications for this. By contrast, the standard SaaS is weaker from a data protection perspective because no clear EU data residency is guaranteed and US/third-country processing is explicitly mentioned.
Sources
- https://dify.ai/privacy
- https://dify.ai/pricing
- https://dify.ai/blog/dify-achieves-soc-2-iso-27001-gdpr-compliance-for-the-second-year-running
- https://dify.ai/blog/dify-open-source
- https://dify.ai/blog/openai-assistants-api-vs-dify-self-hosting-flexible-ai-solutions
- https://dify.ai/blog/dify-x-microsoft-azure-marketplace
- https://dify.ai/jp/enterprise
Strengths & weaknesses at a glance
| Strengths | Weaknesses |
|---|---|
| • Visual agent and workflow builder | • Dify Cloud processes data globally depending on the region, including in the USA, EEA, UK, China, Australia, and Canada |
| • RAG, knowledge pipelines, and document processing | • The Cloud Terms exclude sensitive personal data for certain uses |
| • Cloud and self-hosting | • External plugins and models can create additional data flows |
| • APIs, plugins, observability, and team features | • Production self-hosting instances require DevOps, security, and monitoring |
| • Community edition for your own infrastructure | |
| • The provider’s statements regarding DPA, SOC 2, ISO 27001, and GDPR |
Reviews
0 reviews in total
There are no confirmed reviews for this tool yet.
Submit review
Your review will only become visible after email confirmation. This protects the portal against abuse.
Report review
Please select the reason why this review should be checked.
GDPR-compliant usage possible?
For the EU/EEA area, Dify can be assessed as usable in the best available usage path in a GDPR-compliant manner, because the website on the one hand mentions self-hosting or enterprise deployment in controlled environments and on the other hand describes data protection mechanisms on the SaaS/enterprise side such as Privacy Policy, SCC-based third-country transfers, as well as Data Processing Agreements. For the standard SaaS variant, however, the situation remains less ideal, because the Privacy Policy mentions US servers and also refers to processing in the USA, EEA, and China; therefore, the positive assessment is primarily sustainable via the self-hosted/on-premise or controlled deployment path.
Positive
Positive aspects are the GDPR compliance stated on the website, the reference to comprehensive Data Processing Agreements, the mention of Standard Contractual Clauses for transfers from the EEA/Switzerland to third countries not considered adequate, an EU representative in Ireland, as well as the clearly documented deployment options with 'on-premise, public cloud, VPC' and a self-hosted/open-source offering.
Negative
A negative aspect is that the standard Privacy Policy for cloud/website operation mentions US servers and also describes processing in the USA and China. A specific EU/EEA-exclusive server location for Dify SaaS, an explicit EU data residency commitment, a publicly discoverable subprocessor list, and a clearly findable statement on opting out of general AI training are not specified on the website.
Server location
The Privacy Policy states that website servers are located in the USA and that data may be processed or stored in regions where LangGenius, affiliated companies, or service providers have facilities, including the USA, Australia, Canada, China, and the EEA. A specific EU data center for the SaaS is not specified on the website.