Security at GL Suite.
The commitment is easy to state and hard to keep: know which data each product needs, restrict who can access it, and leave a trail of every important action. This page explains how we do that today.
Fit for the product, the data and the deployment model.
Data minimisation
We collect and keep only what the service needs to work. External integrations request read-only scopes, and you can disconnect at any time.
Access boundaries
Data separated per organisation in the database, with access rules enforced in the database itself. Admin keys stay out of the browser and the team uses two-factor authentication.
Traceable actions
Relevant events are recorded per product: who signed in, what changed, when. Errors go to monitoring with alerts.
Reviewed changes
Nothing reaches production without human review, automated checks and a pass through a preview environment.
Security documentation.
What we provide when your security or procurement team asks for a vendor review.
Per-product documentation
Architecture description, data flow and responsibilities for each engaged product.
Encryption
TLS in transit along the whole path. At rest, encryption is the providers' (Supabase and Vercel), described on the infrastructure page.
Deployment options
Multi-organisation in the standard product, a dedicated project when the contract requires it.
Identity and access
Roles per organisation, invitation by email, immediate revocation. Corporate login depending on product scope.
Vulnerability management
Dependency scanning on every change and fixes by severity. External assessment on request, under contract.
Incident response
Triage, containment, root cause and customer notification, with deadlines set in the data addendum.
The standing answers to a vendor review.
The compliance page gathers what we hold ourselves to, what we are measured against and where each piece of data lives. Without claiming certifications we do not have.
Open the compliance pageReport a vulnerability.
Found something? Write to the address below with as much detail as you can. We reply, fix by severity and give credit if you want it.
contato@glsuite.io