Dify
Dify
Application development and workflow platform for LLM apps with plugin and enterprise features.
Curated by Tiberiu ArvaStale
Strengths
- App + workflow surface in one stack
- Built-in BaaS-style app publishing
- Plugin architecture
Practitioner note
Good fit for teams that want one self-hostable surface for apps, workflows, and model operations, but the license and commercial boundary need review before standardising widely.
Warning
Governance posture
Reviewed 2026-05-26Self-hosted is customer-controlled; Dify Cloud region not publicly documented.
SourceDocker/Kubernetes self-hosted, Dify Cloud SaaS, or enterprise on-prem. (self-hosted, saas, on-prem)
SourceNo dedicated audit-log documentation confirmed on public Dify docs.
SOC 2 Type II (Sensiba), second consecutive year.
SourceISO 27001:2022 (Johanson), second consecutive year.
SourceNot mentioned in Dify's public compliance documentation.
Application/workflow platform tooling; deployer carries obligations for systems built with it. (role: not-applicable)
Modified Apache-2.0 — adds multi-tenant and branding restrictions, outside OSI Apache-2.0. (medium)
SourceEU AI Act obligations
Risk tier: Not applicable · as of 2026-08-23Source-backed information mapped from Dify's tracked risk tier — not legal advice. Obligations depend on how your organisation deploys the system; see the full obligation reference and timeline.
This record's EU AI Act risk tier is marked not applicable, so no tier-specific obligations attach. Deployers embedding it in an AI system in scope of the Act should assess that system's own tier.
Change history
Source-backed and auto-detected events for this tool, newest first.
- Release
Dify 1.16.0 introduced the beta Dify Agent experience with shell-style agent capabilities and Skills packaging.
Release 1.16.0 · langgenius/dify - ReleaseHigh impact
Dify 1.15.0 introduced difyctl for terminal, script, and CI workflow runs, added richer human-in-the-loop workflow forms, and fixed CVE-2026-41948 in plugin-daemon forwarding.
Release 1.15.0 · langgenius/dify - ReleaseHigh impact
Dify 1.14.1 hardened self-hosted SECRET_KEY handling, protected internal metrics endpoints, fixed tenant-isolation issues, and refreshed dependencies for CVE-2026-42208 and related risks.
Security hardening, workflow stability, and cleaner self-hosted deployments · langgenius/dify · GitHub - Release
Dify 1.14.0 introduced collaborative workflow editing with synced graph updates and presence indicators, while keeping collaboration disabled by default for self-hosted deployments.
Release v1.14.0 · langgenius/dify · GitHub - ReleaseDify 1.13.3 ships workflow and retrieval stability fixes
Dify v1.13.3 shipped on March 27 with workflow, streaming, and knowledge-retrieval stability fixes, reinforcing its push toward more reliable production orchestration.
Releases · langgenius/dify - Auto-detectedgithubStars: 148466 → 151300
From snapshot diff 2026-07-17 → 2026-08-04.
- Auto-detectedlastRelease: 2026-06-25 → 2026-07-28
From snapshot diff 2026-07-17 → 2026-08-04.
- Auto-detectedversion: 1.15.0 → 1.16.1
From snapshot diff 2026-07-17 → 2026-08-04.
- Auto-detectedgithubStars: 144221 → 148466
From snapshot diff 2026-06-07 → 2026-07-17.
- Auto-detectedlastRelease: 2026-05-19 → 2026-06-25
From snapshot diff 2026-06-07 → 2026-07-17.
- Auto-detectedversion: 1.14.2 → 1.15.0
From snapshot diff 2026-06-07 → 2026-07-17.
Explore the category
Compare this tool against the rest of its category and the cloud platform foundation layer.
Return to the category grid to compare governance posture across every tracked tool.
Review Microsoft Foundry, Amazon Bedrock, and Gemini Enterprise Agent Platform as the foundation layer.
Track releases, deprecations, license changes, and other market movements.