Trust & Security

Security is not a
feature. It's the foundation.

GlideHubAi is built for the most regulated environments in the world. SOC 2 Type II certified, ISO 27001 accredited, and GDPR-compliant by design — not by checkbox.


SOC 2
Type II Certified
Annual renewal
ISO 27001
Accredited
2022 revision
GDPR
Compliant
Article 32 ready
HIPAA
BAA Available
Healthcare ready
VAPT
Pen Tested
Quarterly external

Your data.
Your control. Always.

GlideHubAi was architected from day one for environments where a single data breach is existential. Every design decision reflects that.

  • AES-256 encryption at rest — All configuration backups, logs, and metrics encrypted with AES-256. Keys managed via HashiCorp Vault or customer-managed KMS (AWS, Azure, GCP).
  • TLS 1.3 in transit — All API calls, UI sessions, and inter-service communication encrypted with TLS 1.3 minimum. TLS 1.0/1.1 deprecated.
  • Data residency options — Choose your data region: India, EU (Frankfurt), APAC (Singapore), US-East, US-West. Data never leaves your selected region.
  • Field-level encryption — Credentials, passwords, and SNMP community strings stored with additional field-level encryption beyond database-level.
  • Immutable audit logs — Platform audit trail stored on write-once storage with cryptographic hash chaining — tamper-evident by design.
  • Role-based access control — Granular RBAC with predefined roles (Admin, Operator, Viewer, Auditor) and custom role builder.
  • SAML 2.0 / OIDC SSO — Native integration with Okta, Azure AD, PingFederate, Google Workspace, and any SAML 2.0 IdP.
  • MFA enforcement — TOTP, hardware FIDO2 keys, and push-based MFA. Policy enforcement per role — admins can require MFA for all high-privilege actions.
  • Just-in-time access — Temporary elevated access for maintenance windows — auto-expires, fully logged, and requires approval workflow.
  • API key scoping — API keys scoped to specific resources, methods, and IP ranges. Automatic rotation reminders with zero-downtime key rotation support.
  • Private deployment option — Full on-premises deployment in your air-gapped environment — same capabilities, zero public internet dependency.
  • IP allowlisting — Restrict platform access to specific corporate IP ranges or VPN exit nodes.
  • Private link connectivity — AWS PrivateLink, Azure Private Endpoint, GCP Private Service Connect — platform traffic never traverses the public internet.
  • Collector network segmentation — Monitoring collectors can operate in DMZs with outbound-only communication — no inbound ports required from the internet.
  • Network policy enforcement — Kubernetes NetworkPolicy enforces zero-trust inter-service communication within the platform microservice architecture.
  • Quarterly penetration testing — External VAPT conducted by CREST-certified firms. Reports available to enterprise customers under NDA.
  • Vulnerability management — All dependencies scanned with Snyk and Trivy. CVE patching SLA: Critical in 24h, High in 72h, Medium in 14 days.
  • Bug bounty program — Responsible disclosure program via HackerOne. Security researchers rewarded for valid findings.
  • SOC 2 Type II audit — Annual SOC 2 Type II audit covering Security, Availability, and Confidentiality trust service criteria. Report available under NDA.
  • Security training — All engineers complete quarterly security training. Annual threat modelling workshops per product team.
Compliance Coverage Matrix
FrameworkCoverageEvidence Auto-Generated
PCI DSS v4.0Full
ISO 27001:2022Full
SOC 2 Type IIFull
HIPAA Technical SafeguardsFull
NIST CSF 2.0Partial
CIS Controls v8Full
GDPR Article 32Full
SOX IT ControlsPartial
DORA (EU)Partial
FedRAMP (In Progress)2025 Q4
Enterprise Security Review
Request our full security documentation pack: SOC 2 report, penetration test summary, ISMS policy index, and data processing agreement. Available to qualified enterprise prospects under NDA.

Security questions?
Our CISO is ready to talk.