Trust & Security
How we protect your business and customer data.
SOC 2 Type I in progress
We are currently undergoing independent auditing for SOC 2 Type I compliance, expected Q3 2026.
Encryption at Rest & Transit
All data is encrypted in transit using TLS 1.3 and at rest using AES-256. Database backups are encrypted.
Hostinger Infrastructure
Glimmio is hosted on Hostinger cloud infrastructure in Mumbai, India. Datastores are isolated on an internal network behind a single TLS-terminating proxy.
No Third-Party AI Training
Our AI providers (Anthropic, OpenAI) are strictly bound by enterprise agreements not to train their models on Glimmio API data.
Authentication & Authorization
Glimmio uses standard OAuth 2.0 flows for all integrations (Meta, Google, Shopify). We never store your passwords for these platforms. Access tokens are encrypted at rest.
Within Glimmio, role-based access control (RBAC) ensures users only have access to authorized workspaces and actions. Features like Action Execution require explicit Manager/Admin level permissions.
Vulnerability Management
We run continuous automated dependency scanning and weekly container image scans. We partner with external security researchers for responsible disclosure of vulnerabilities.
If you believe you have found a security vulnerability in Glimmio, please email security@glimmio.com.
Compliance
Glimmio acts as a Data Processor under GDPR and a Service Provider under CCPA. We process data strictly to provide the Glimmio service.