Gigets

Security

Version 1.0 · 31 July 2026

What Gigets owns is the trust between its members, so security is the condition of the product working at all.

This page says what is true today and what is not yet true. We would rather tell you what is missing than let you assume it is not.

What protects your data today

In transit. Everything between you and Gigets travels over TLS. HTTP Strict Transport Security is enforced.

At rest. Member data is encrypted at rest with AES-256 by our infrastructure provider.

Where it lives. Primary storage of member data is in the European Union. Where processing happens elsewhere it is covered by Standard Contractual Clauses. The full list will be published on the Subprocessors page in the legal index.

Who can reach it. Access to member data is granted per person, for a stated reason, and revoked the day it stops being needed. A departure revokes access the same day. Every access to member data is itself logged.

Accounts. Two-factor authentication is required on every internal account that touches member data, code, or infrastructure. Credentials are never shared.

Tooling. Member data never passes through a tool we have not approved. Convenience is not a reason.

Deletion. Erasure and export are tested end to end, including our search indexes and vector stores, before members are admitted rather than after. An untested deletion path does not exist.

Purpose limitation. Exchange conversations are read only for safety, disputes, and aggregate signals, and every access is logged.

What is not true yet

We are a small company building toward launch. The following are on the roadmap and are not in place today. Anyone who tells you otherwise, including us, would be wrong.

StatusTrigger
Independent penetration testNot doneBefore public launch
SOC 2 Type IINot startedRequired before selling to organisations. Type II needs an observation window of three to twelve months, so it must begin roughly a year before the first organisation contract
ISO/IEC 27001Not startedFollows SOC 2, or replaces it if the first large buyers are European
Formal bug bountyNot startedAfter launch, once there is enough surface to be worth a researcher's time
24/7 on-callNot in placePost-launch, at scale

We do not claim SOC 2 compliance and you will not find that claim anywhere on this site. Compliance means an audit report signed by an independent firm. Until that report exists, saying it would be false.

Reporting a vulnerability

If you have found something, tell us. We would rather hear it from you.

[email protected]

Please give us enough to reproduce it. Please do not access, modify, or delete data belonging to anyone else, do not degrade the service, and do not disclose publicly until we have had a chance to fix it.

Our commitment to you: we acknowledge within 2 working days, we tell you what we found within 10, we fix what needs fixing, we credit you if you want to be credited, and we will not pursue legal action against anyone who reports in good faith and follows the guidance above.

Our machine-readable policy is at /.well-known/security.txt.

If something goes wrong

Any suspected compromise reaches the founder within the hour. Concealing a breach is treated more seriously here than causing one.

Where a breach is likely to result in a risk to members, we notify the supervisory authority within 72 hours and we tell affected members directly, without undue delay, in plain language: what happened, what data was involved, what we did, and what you should do.

What you can do

Turn on two-factor authentication. Use a password you use nowhere else. Keep arrangements inside Gigets until you are comfortable moving them. Tell us at [email protected] the moment you think someone else has access to your account.

Vulnerabilities, privacy questions, and reports of harm all reach us at [email protected].