We respect your privacy
Gearbox uses only essential cookies and local storage to keep the site and platform working — no advertising or analytics cookies. See our Privacy Policy for details.
Security & Compliance
This is the only page on the site that lives in the dark — because your asset lifecycle data is business-critical, and we treat it that way. Audited controls, encryption everywhere, and policies you can actually read.
Vault register · lit edges · the only all-dark page on the site
The compliance masthead
Each control, its real status, and the evidence behind it. Nothing certified is claimed as certified — 'in progress' says in progress.
The audit is underway. The controls it covers — encryption, access control, change management, availability — are already enforced across the platform, and the platform-wide audit log records every sensitive action.
Evidence: audit engaged · report under NDA on completion
Certification is planned after SOC 2 Type II completes — the same evidence base, the same controls, one audit program at a time.
Evidence: listed on our security roadmap · no claim of certification
SAML 2.0 and OIDC single sign-on are live — connect Okta, Microsoft Entra ID, Google Workspace, or any standards-compliant identity provider. Sign-in flows through your IdP with JIT user provisioning and group-to-role mapping. SCIM 2.0 user provisioning is available today for Okta and Microsoft Entra ID.
Evidence: SAML 2.0 + OIDC live · JIT provisioning · SCIM 2.0 live
Dedicated, single-tenant deployments are available on Enterprise plans. Multi-tenant environments isolate customer data at the application and database layers.
Evidence: dedicated deployments · app + DB isolation
Production data is hosted in the United States by default. EU residency is available on Enterprise contracts — deployments can be provisioned in an EU region, with data and backups staying in that region.
Evidence: US default · EU on Enterprise · same-region backups
A contractual 99.9% uptime SLA on Enterprise plans — and a live status page, embedded below, so you can watch it yourself instead of taking our word.
Evidence: SLA in Enterprise contract · live status page
System status
Not a screenshot, not a promise — the actual status page, embedded. This is the same page our customers watch.
The number we contract to
99.9%
Uptime SLA, on Enterprise contracts. The status page above is the receipt — verified live, not quoted.
Security controls
Enforced at every layer of the platform — not bolted on after the fact.
01
All traffic is encrypted with TLS 1.3. Data at rest is encrypted with AES-256 — databases, backups, and object storage. Keys are managed per-tenant where required.
TLS 1.3 · AES-256
02
Named roles — admin, planner, procurement, engineer, viewer — enforce least privilege across the platform. Every user has a named identity; no shared accounts.
RBAC · least privilege
03
Every sensitive action — configuration changes, data exports, access grants, and authentication events — is written to an append-only audit log with actor, timestamp, before/after state, request ID, and source IP. Admins can review and export the log, filtered by resource, actor, or time window; retention is governed by the operator's audit-log policy.
Append-only log · actor + before/after state · filterable export
04
Continuous dependency scanning and regular penetration testing. Critical vulnerabilities are patched with priority and communicated to affected customers.
Scanning · pen tests · disclosure policy
Residency & subprocessors
The list of who touches your data is short — and fully transparent.
Production data is hosted in the United States by default. EU data residency is available for Enterprise contracts — deployments can be provisioned in an EU region, with data and backups staying in that region.
We use a small set of subprocessors to run the platform: Railway for cloud infrastructure and hosting (United States), and Railway managed PostgreSQL for database hosting (US or EU per deployment). Every subprocessor is bound by a data processing agreement and access is limited to what the service requires.
Complete, current list maintained in the DPA
Vulnerability policy
We believe security researchers make our platform stronger. If you find a vulnerability, we want to hear about it — and we commit to fixing it.
Report vulnerabilities to security@gearbox.ai. Please include a description of the issue, steps to reproduce, and the affected version. We acknowledge reports within 48 hours and provide a status update within 5 business days. We commit to a 90-day fix window for confirmed vulnerabilities and coordinate public disclosure with you.
Good-faith research conducted under this policy is authorized, and we will not pursue legal action against researchers who follow it. Out of scope: denial of service attacks, social engineering, and testing against production tenants other than your own.
Security FAQ
Asked and answered up front — no deflection, no sales runaround.
SOC 2 Type II is in progress. The controls it covers — encryption, access control, change management, availability — are already enforced across the platform, and the platform-wide audit log records every sensitive action. Once the audit completes, the report is available to customers under NDA.
Production data is hosted in the United States by default. EU data residency is available on Enterprise contracts — deployments can be provisioned in an EU region, with data and backups staying in that region.
Yes. SAML 2.0 and OIDC single sign-on are live — connect Okta, Microsoft Entra ID, Google Workspace, or any standards-compliant identity provider. Sign-in flows through your IdP with JIT user provisioning and group-to-role mapping. SCIM 2.0 user provisioning is available today for Okta and Microsoft Entra ID.
Only named Gearbox employees with a business need, under least-privilege RBAC. Every sensitive action — configuration changes, data exports, and access grants — is recorded in the platform-wide append-only audit log. We never sell customer data and never use it to train models for other customers.
Yes. Our Data Processing Agreement is available at /legal/dpa, and we are happy to sign your organization’s DPA where terms are mutually acceptable.
Continuous dependency scanning plus penetration testing. Confirmed vulnerabilities are patched with priority — critical issues within our published SLA — and we disclose fixes to affected customers. See our responsible disclosure policy below.
Send us your security questionnaire or ask for our review package — we respond within one business day.
Type: Fraunces variable · Register: vault · Light: one glow source · Grain: 2% — this page is the product