From infrastructure to internal access controls, we treat client data with the standards our regulated clients require.
SOC 2 Type II certified. ISO 27001 aligned. Annual third-party penetration testing.
SSO, MFA and role-based access controls across the portal. Session activity is logged and available to client administrators.
All data is encrypted in transit (TLS 1.2+) and at rest (AES-256). Backups are geo-redundant, and data residency options are available for regulated clients.
Please email security@gafigroup.com. We aim to acknowledge reports within one business day.