The Register / Agent-building platforms / Dify
Register entry · Agent-building platforms · updated 26 Sept 2026
Dify
Dify is a visual platform for building chat apps, agentic workflows and RAG knowledge bases on top of many model providers. It can be self-hosted with Docker (Community Edition), used as Dify Cloud, or deployed as Dify Enterprise. The code is published under the Dify Open Source License, an Apache-2.0-derived licence with extra conditions (for example on multi-tenant SaaS use), so it is not OSI open source. Version 1.16 (July 2026) added a beta shell-based 'Dify Agent' with sandboxed execution.
What reviewers and users praise
- Independent reviewers rate it among the stronger open-source AI app builders (aitoolradar 4.4/5, SaaS Compared)
- Some users see it as a direct starting point for knowledge-base apps (Reddit)
- Self-hostable, with published SOC 2 Type II and ISO 27001 for the commercial offering
What they criticise
- Several users describe its RAG retrieval quality as weak (Reddit, August 2026)
- Customising beyond the visual builder is reported to be hard (Reddit)
- Recurring high-severity advisories, including cross-tenant data exposure, in 2026
| Price | Free, paid from $590 |
|---|---|
| Use it via | Web app, API, MCP server |
| Runs on | web, linux, macos, windows |
| Licence | LicenseRef-Dify-Open-Source-License |
| Updated | Evidence collected 26 Sept 2026 |
How the rating was worked out
Weights for Agent-building platforms: adoption 35%, experts 35%, crowd 30%. Pillars without enough evidence are left out and the others re-weighted. The method.
| Adoption & momentumweight 35% | 86 | GitHub stars 157k → 97 · 5 releases in 90 days → 60reach × 0.7 + momentum × 0.3 |
|---|---|---|
| Expertsindependent reviews · weight 35% | — | Only 1 independent review (3 needed) |
| Crowdcommunity sample · weight 30% | 40 | 9 dated posts from reddit, hackernews: 2 positive · 2 mixed · 5 negative (positive + ½ mixed) ÷ n, averaged toward 50 for small samples |
| Rating | 65 | Provisional: low confidence (2 of 3 pillars, 9 community posts). |
Evidence checks. 3 reviews from tool directories, AI-written pages or unnamed authors not counted. 1 post over the three-per-thread limit not counted. How evidence is checked.
Trust & safety
Seven dimensions graded A–D from documented facts. Overall: B.
Permission model
Dify Agent (beta, 1.16+) runs shell/code in a local sandbox or E2B cloud sandbox; release notes warn to offer it 'only to trusted, non-malicious users'. Per-action approval modes not established. source
Data access scope
Not established.
Data storage
Community Edition and Enterprise can be self-hosted (Docker Compose, VPC); Dify Cloud optional. source
Data retention & training
Privacy policy: 'we will not use your AI interaction data for model training'; sub-processor model providers are contractually barred from training. Retention period is 'as long as necessary' (no fixed period); Sandbox plan keeps 30-day logs. source
Incident history (24 months)
21 GitHub security advisories published 2024-09-26 to 2026-09-26 (8 high, none rated critical), including cross-tenant data disclosure and an unauthenticated SSRF, all with fixes. HN commenters also cite a 'React2Shell' incident affecting Dify (not independently verified here). source
Compliance
dify.ai states Dify Enterprise holds 'SOC 2 Type II + ISO 27001'; pricing page shows GDPR, AICPA SOC 2 and ISO 27001 badges. source
Transparency
Source published on GitHub under an Apache-2.0-derived licence with additional conditions (not OSI-approved); detailed public release notes. source
The experts
1 named independent reviews found; dated reviews from the last 12 months are scored.
- mixed
Dify democratizes AI agent building, but it's not magic. You still need to understand how AI works
Nova (dev.to) · 24 Apr 2026 · dev.to
The crowd
9 coded posts from reddit, hackernews.
- negative
I wish I could say this but Dify's retrieval is not decent from any level. It needs a lot of improvement.
r/AI_Agents · 14 Aug 2026 · reddit.com - negative
Dify's RAG is definitely rough compared to Copilot Studio.
r/AI_Agents · 14 Aug 2026 · reddit.com - positive
Dify is probably the best starting point for the content-generation and knowledge-base part.
r/AI_Agents · 11 Aug 2026 · reddit.com - negative
Personally my experience with rag on dify was not satisfactory.
r/AI_Agents · 18 Aug 2026 · reddit.com - mixed
the knowledge base thing works fine but the ingestion on big pdfs can be slow sometimes.
r/AI_Agents · 18 Aug 2026 · reddit.com - mixed
Dify is great until you try to customize the underlying python
r/AI_Agents · 26 May 2026 · reddit.com - positive
all generated by one Dify workflow in under 60 seconds.
r/AI_Agents · 21 Apr 2026 · reddit.com - negative
Zapier's npm account (425 packages, Shai Hulud malware) and Dify's React2Shell incident both followed the same vector
Tell HN: Litellm 1.82.7 and 1.82.8 on PyPI are compromised · 25 Mar 2026 · news.ycombinator.com
Pricing
As published, checked 26 Sept 2026.
| Plan | Price | Notes |
|---|---|---|
| Community (self-hosted) | Free | All core features in the public repository. |
| Sandbox (cloud) | Free | 200 message credits, 1 member, 5 apps, 30-day log history. |
| Professional (cloud) | $590 / yearly | $590 per workspace/year; 5,000 message credits/month, 3 members, 50 apps. |
| Team (cloud) | $1590 / yearly | $1590 per workspace/year; 10,000 message credits/month, 50 members, 200 apps. |
| Enterprise | Custom | Contact sales; SSO, VPC/self-hosted deployment. |
Recent changes
- 10 Sept 2026
Dify 1.17.1: dataset-scoped knowledge base; path traversal fix; staged Weaviate upgrade required for self-hosters. source
- 25 Aug 2026
Dify 1.17.0: E2B cloud sandbox backend for Dify Agent, home snapshots and skill management. source
- 17 Jul 2026
Dify 1.16.0: introduces Dify Agent (beta), a shell-based agent experience. source
- 28 Jul 2026
Dify 1.16.1: multi-select tool inputs and workflow node locator. source
Ranked alongside
Other ranked entries in Agent-building platforms.
Sources
Every figure above traces to one of these, observed up to 26 Sept 2026.