Skip to content
Security

Security and compliance

The controls below are the ones we get asked to evidence in procurement. Each is implemented in the pipeline rather than described in a policy document.

  1. 01

    Data security

    Data is encrypted with AES-256 at rest and TLS 1.2 or better in transit. Keys are managed in a dedicated key service with rotation, and access to production data requires a named approval that is itself logged.

    • AES-256 at rest
    • TLS 1.2 minimum in transit
    • Approved, logged production access
  2. 02

    Application security

    Dependencies are scanned continuously, changes go through review before merge, and we run external penetration testing on a fixed schedule with findings tracked to closure.

    • Continuous dependency scanning
    • Mandatory review before merge
    • Scheduled external penetration testing
  3. 03

    Compliance and data protection

    We operate under GDPR and CCPA, with ISO/IEC 27001-aligned controls. Lawful basis is recorded per data category and retention is enforced by the pipeline, so data ages out whether or not somebody remembers to delete it.

    • GDPR and CCPA workflows
    • ISO/IEC 27001-aligned controls
    • Retention enforced in the pipeline
  4. 04

    Audit and monitoring

    Every lookup writes an immutable record tied to the key that made it. Infrastructure and application logs are centralised, alerted on, and retained for the period your agreement specifies.

    • Immutable per-call records
    • Centralised logging and alerting
    • Exportable audit trail
  5. 05

    Privacy management

    Deletion, correction and opt-out requests propagate through every downstream index rather than stopping at the primary store. We can show you the propagation record for any completed request.

  6. 06

    Responsible AI

    Models are evaluated continuously against held-out data, and we monitor for drift rather than assuming yesterday's calibration still holds. We do not infer protected characteristics, and we decline use cases we would not defend publicly.

    • Continuous evaluation and drift monitoring
    • No inference of protected characteristics
    • Published acceptable-use policy
  7. 07

    Security contact

    Report a vulnerability or request our security documentation at info@gscplatform.co. We acknowledge reports within one business day.

Contact address

Damir Ialalov2/A Aghbyur Serob St., apt. 20Yerevan, Armenia

Contact