Security

Security at GL Suite.

The commitment is easy to state and hard to keep: know which data each product needs, restrict who can access it, and leave a trail of every important action. This page explains how we do that today.

Core controls

Fit for the product, the data and the deployment model.

Data minimisation

We collect and keep only what the service needs to work. External integrations request read-only scopes, and you can disconnect at any time.

Access boundaries

Data separated per organisation in the database, with access rules enforced in the database itself. Admin keys stay out of the browser and the team uses two-factor authentication.

Traceable actions

Relevant events are recorded per product: who signed in, what changed, when. Errors go to monitoring with alerts.

Reviewed changes

Nothing reaches production without human review, automated checks and a pass through a preview environment.

Commercial review

Security documentation.

What we provide when your security or procurement team asks for a vendor review.

Per-product documentation

Architecture description, data flow and responsibilities for each engaged product.

Encryption

TLS in transit along the whole path. At rest, encryption is the providers' (Supabase and Vercel), described on the infrastructure page.

Deployment options

Multi-organisation in the standard product, a dedicated project when the contract requires it.

Identity and access

Roles per organisation, invitation by email, immediate revocation. Corporate login depending on product scope.

Vulnerability management

Dependency scanning on every change and fixes by severity. External assessment on request, under contract.

Incident response

Triage, containment, root cause and customer notification, with deadlines set in the data addendum.

Compliance

The standing answers to a vendor review.

The compliance page gathers what we hold ourselves to, what we are measured against and where each piece of data lives. Without claiming certifications we do not have.

Open the compliance page
Coordinated disclosure

Report a vulnerability.

Found something? Write to the address below with as much detail as you can. We reply, fix by severity and give credit if you want it.

contato@glsuite.io
Security | GL Suite