In transit
All API traffic is encrypted with TLS 1.3. HTTPS is enforced on every endpoint. No plaintext communication is permitted.
Gateplex is deployed inside regulated institutions. This page states how data is protected, where it lives, and what our compliance posture actually is today.
All API traffic is encrypted with TLS 1.3. HTTPS is enforced on every endpoint. No plaintext communication is permitted.
Intercept data is stored with AES-256 encryption.
Row-level security is enforced at the database layer. Every query is scoped to the authenticated organisation, so cross-tenant access is not possible.
Keys are hashed before storage and are never shown again after creation. They do not appear in logs, and they can be rotated or revoked instantly.
EU, US, UK, or GCC and MENA residency on Enterprise plans. Data does not leave the configured region.
Every intercept record stores a SHA-256 hash of its own content together with the hash of the record immediately preceding it.
Chain integrity is verified when a compliance report is generated. Deleting or modifying any record breaks the chain, and the break is detectable. This is what separates an audit trail from an application log.
| Programme | Status | Detail |
|---|---|---|
| SOC 2 Type II | [Planned] | SOC 2 Type I preparation is planned for a future phase; not yet started. We hold no compliance certification today and claim none. |
| GDPR | [Processor role] | We act as a data processor for customer data. Data subject access request workflows are supported and a DPA is available on request. |
| EU AI Act | [Mapped to Articles 12, 14, and 50] | Record-keeping, human oversight, and transparency obligations are mapped to product capabilities, with exports formatted for regulatory review. |
Dashboard permissions are role scoped. Approval decisions are restricted to authorised reviewers and recorded against a server-derived identity.
SAML and OIDC, including Okta, Microsoft Entra ID, and Google Workspace, available on Enterprise plans.
Responsible disclosure at security@gateplex.ai. Valid reports are acknowledged within 48 hours, under a 90-day disclosure policy.
For organisations with strict data sovereignty requirements, Gateplex can be deployed entirely within your own cloud environment or on-premises, including air-gapped installations. Agent payloads, audit records, and governance decisions never leave your perimeter, and policy synchronisation uses an encrypted outbound-only channel.