Security
What we have, what we don’t, who to ask.
GigLogix holds your jobs, clients, crew, and invoices, so here’s exactly how we protect them. We’re a small team, not a 200-person security org. This page lists the controls we run today, the ones we don’t have yet, and the inbox to email with questions.
Encryption and hosting
- In transit
- HTTPS only, TLS 1.2 or newer. The app and sign-in pages send HSTS headers so browsers refuse plain HTTP.
- At rest
- The database uses Azure SQL transparent data encryption. Integration credentials and other sensitive fields are encrypted again in our own code with AES-256-GCM.
- Backups
- Automated database backups with point-in-time restore, stored geo-redundantly. A scheduled job restores a backup every week to prove it works.
- Where it lives
- Your data is hosted on Microsoft Azure in the United States. We don’t offer an EU region today.
Sign-in and access
- Sign-in
- A hosted GigLogix sign-in page with email and password, a magic link, or Microsoft 365 / Google. Passwords are stored only as bcrypt hashes.
- Two-factor
- Turn on two-factor with any authenticator app (TOTP).
- Roles
- Each person gets a role in each workspace: Owner, Admin, or Member.
- Workspace isolation
- Every workspace’s data is kept separate. The API checks that you belong to a workspace before it returns anything from it.
- Sessions
- Access tokens expire after 15 minutes. Refresh tokens change every time they’re used, and a reused one is caught. Signing keys rotate every 30 days.
- What we don’t have
- No SAML single sign-on today. If your IT team requires it, GigLogix isn’t a fit yet.
Your data
- Audit log
- Workspace admins can see a log of who changed what, and when.
- Export any time
- A workspace Owner or Admin can download everything as JSON and CSV whenever they want. No lock-in.
- Access and deletion requests
- We can export or erase a person’s data on request. Records the law requires us to keep, like invoices and payroll, are anonymized instead of deleted.
- Card payments
- Your clients pay on Stripe’s hosted page. GigLogix never sees or stores full card numbers.
- No selling
- We don’t sell your data or your clients’ data, and we don’t share it with advertisers.
Who else handles your data.
The outside services that process customer data, and when. Integrations only see data once you connect them.
| Service | What it does | When |
|---|---|---|
| Microsoft Azure | Hosting, database, and file storage. Azure Communication Services sends email and SMS. Azure AI Vision reads equipment labels during inventory audits. | Always |
| Stripe | Invoice payments | Always |
| Sentry | Error monitoring | Always |
| Cisco Meraki | Event WiFi network setup (SSIDs, VLANs) | Event WiFi, coming soon — not used for your workspace today |
| Intuit QuickBooks Online | Accounting sync (Professional and Venue) | Only if you connect it |
| Gusto, Dataddo | Payroll import (Professional and Venue) | Only if you connect it |
| Mews | Hotel PMS integration (Venue plan) | Only if you connect it |
| Google Analytics, Plausible | Marketing-site analytics | Only after you accept analytics cookies |
Certifications, honestly.
The short version: we don’t have a SOC 2 report yet.
SOC 2
We’re putting the controls and evidence in place, but there’s no audit report to share today. We won’t promise a date we can’t back up. If your vendor review needs one, email us and we’ll tell you where things stand.
Card data (PCI)
Card payments run on Stripe’s hosted pages, so card numbers go to Stripe, not to us. Stripe carries the PCI work for card handling.
Who to ask.
Real inboxes, read by the people who run GigLogix.
Try GigLogix with your own data.
Start a 14-day free trial with no card. Export everything whenever you want.