Security posture • Defense-grade

Built to be reviewed, not just trusted.

Gateplex is deployed inside regulated institutions. This page states how data is protected, where it lives, and what our compliance posture actually is today.

Active Infrastructure Health SurfaceAll_Systems_Nominal
Cryptographic Verification
SHA-256 CHAINED
Chain verified01
Network Boundary
INLINE VPC PROXY
Node active02
Encryption Layer
TLS 1.3 / AES-256
Solid03
posture / continuousno plaintext egress

Data protection.

[CIPHER: TLS_1_3]

In transit

All API traffic is encrypted with TLS 1.3. HTTPS is enforced on every endpoint. No plaintext communication is permitted.

[STORAGE: AES_256]

At rest

Intercept data is stored with AES-256 encryption.

[ISOLATION: ROW_LEVEL]

Tenant isolation

Row-level security is enforced at the database layer. Every query is scoped to the authenticated organisation, so cross-tenant access is not possible.

[CUSTODY: HASHED]

API key custody

Keys are hashed before storage and are never shown again after creation. They do not appear in logs, and they can be rotated or revoked instantly.

[RESIDENCY: PINNED]

Data residency

EU, US, UK, or GCC and MENA residency on Enterprise plans. Data does not leave the configured region.

[INTEGRITY: SHA_256_CHAIN]

Tamper evidence.

Every intercept record stores a SHA-256 hash of its own content together with the hash of the record immediately preceding it.

Chain integrity is verified when a compliance report is generated. Deleting or modifying any record breaks the chain, and the break is detectable. This is what separates an audit trail from an application log.

intercept · hash · chain integrity verified
REC_0091prev3b70…c1189f2c…a41d
REC_0092prev9f2c…a41dc4e1…77b9
REC_0093prevc4e1…77b91d8a…09f5
REC_0092*modifiedchain broken · detected at report time

Compliance posture, stated plainly.

ProgrammeStatusDetail
SOC 2 Type II[Planned]SOC 2 Type I preparation is planned for a future phase; not yet started. We hold no compliance certification today and claim none.
GDPR[Processor role]We act as a data processor for customer data. Data subject access request workflows are supported and a DPA is available on request.
EU AI Act[Mapped to Articles 12, 14, and 50]Record-keeping, human oversight, and transparency obligations are mapped to product capabilities, with exports formatted for regulatory review.

Access and disclosure.

Role-based access control

Dashboard permissions are role scoped. Approval decisions are restricted to authorised reviewers and recorded against a server-derived identity.

Enterprise SSO

SAML and OIDC, including Okta, Microsoft Entra ID, and Google Workspace, available on Enterprise plans.

Vulnerability disclosure

Responsible disclosure at security@gateplex.ai. Valid reports are acknowledged within 48 hours, under a 90-day disclosure policy.

Zero-egress boundary

VPC and on-premises deployment.

For organisations with strict data sovereignty requirements, Gateplex can be deployed entirely within your own cloud environment or on-premises, including air-gapped installations. Agent payloads, audit records, and governance decisions never leave your perimeter, and policy synchronisation uses an encrypted outbound-only channel.

Payloads, records, and decisions remain inside your perimeter