Trust & Security

How we protect your business and customer data.

SOC 2 Type I in progress

We are currently undergoing independent auditing for SOC 2 Type I compliance, expected Q3 2026.

Encryption at Rest & Transit

All data is encrypted in transit using TLS 1.3 and at rest using AES-256. Database backups are encrypted.

Hostinger Infrastructure

Glimmio is hosted on Hostinger cloud infrastructure in Mumbai, India. Datastores are isolated on an internal network behind a single TLS-terminating proxy.

No Third-Party AI Training

Our AI providers (Anthropic, OpenAI) are strictly bound by enterprise agreements not to train their models on Glimmio API data.

Authentication & Authorization

Glimmio uses standard OAuth 2.0 flows for all integrations (Meta, Google, Shopify). We never store your passwords for these platforms. Access tokens are encrypted at rest.

Within Glimmio, role-based access control (RBAC) ensures users only have access to authorized workspaces and actions. Features like Action Execution require explicit Manager/Admin level permissions.

Vulnerability Management

We run continuous automated dependency scanning and weekly container image scans. We partner with external security researchers for responsible disclosure of vulnerabilities.

If you believe you have found a security vulnerability in Glimmio, please email security@glimmio.com.

Compliance

Glimmio acts as a Data Processor under GDPR and a Service Provider under CCPA. We process data strictly to provide the Glimmio service.