G
Trust security@gigplux.com

Security

Security is where GigPlux started. Our CEO leads it directly, and every product is designed with it in mind from the first line of code. This page explains how we protect data today and where we are honestly still building.

Philosophy

Security is a design decision, not a feature we add later.

We treat security as part of how a product is built, not a layer bolted on before launch. That means least-privilege access, encrypted data by default, and code reviewed with an attacker's mindset. Our founder's background is in cybersecurity, so this is not an afterthought at GigPlux.

Honesty first

We tell you what we have and what we don't.

We are an early company. We will not claim certifications we do not hold or controls we have not implemented. Everything on this page is either in place today or clearly marked as a goal. If you need something specific for a review, ask us and we will answer directly.

Responsible disclosure

Found something? Tell us.

We welcome reports from security researchers and treat them seriously.

If you believe you have found a vulnerability in any GigPlux product or system, email security@gigplux.com with enough detail for us to reproduce it. Please give us a reasonable window to investigate and fix the issue before making it public.

  • We acknowledge reports within two business days.
  • We keep you updated on our progress toward a fix.
  • We will not pursue action against researchers acting in good faith.
  • Please do not access, modify, or delete data that is not yours while testing.
Encryption

Encrypted in transit and at rest.

No. 01

In transit

All traffic to and from our products runs over HTTPS using modern TLS. Connections are encrypted end to end, and we redirect insecure requests to secure ones. Strict transport policies keep browsers on encrypted connections.

No. 02

At rest

Data stored by our products is encrypted at rest using industry-standard AES-256 through our infrastructure providers. Credentials and secrets are stored using strong one-way hashing, never in plain text.

Data protection

Least data, least access.

No. 01

Data minimization

We collect only what a product needs to work. Less stored data means less to protect and less at risk if something goes wrong.

No. 02

Access control

Internal access follows least privilege. Team members only reach the systems their role requires, and access is reviewed as the team changes.

No. 03

Your rights

You can request access to or deletion of your personal data. See our Privacy Policy for how we handle and retain information.

Infrastructure

Built on trusted foundations.

No. 01

Reputable providers

We run on established cloud and hosting providers with their own strong physical and network security controls, rather than managing bare metal ourselves.

No. 02

Isolation & backups

Production environments are separated from development, and important data is backed up so it can be restored if something fails.

No. 03

Monitoring

We log and monitor for unusual activity so we can respond quickly, and we patch dependencies as security updates are released.

Compliance goals

Where we are headed.

These are goals, not current certifications. We list them so you know our direction.

Goal Audit

SOC 2

As our products reach general availability and our customer base grows, we plan to pursue a SOC 2 Type II examination of our security controls. We are building our practices with that framework in mind, but we do not hold a SOC 2 report today.

Goal Standard

ISO 27001

Longer term, we aim to formalize our information security management system against ISO 27001. This is a future goal that depends on company maturity, and we are not certified against it yet.

Security contact

Questions about our security?

Whether you are reporting a vulnerability or completing a vendor review, reach the security team directly at security@gigplux.com.