Trust & Security

Enterprise-grade
security.

Your business data deserves serious protection. Here is exactly how Gunimi secures it — from storage to access to AI processing.

Encryption

  • All data encrypted at rest using AES-256
  • All data encrypted in transit via TLS 1.3
  • Database credentials and secrets managed via environment-level secrets, never in source code
  • API keys are never exposed client-side

Infrastructure

  • Hosted on Supabase — SOC 2 Type II compliant infrastructure
  • Data stored in EU regions by default
  • Automatic backups with point-in-time recovery
  • Redundant, highly available architecture

Workspace isolation

  • Every workspace is strictly isolated at the data layer
  • Row-level security (RLS) enforced at the database level, not just the application layer
  • No cross-workspace data access is possible by design
  • Workspace-scoped permissions for every resource

Authentication & access

  • Secure email + password authentication via Supabase Auth
  • OAuth 2.0 support with server-side state verification
  • Session tokens are short-lived and rotated automatically
  • Password reset flows are rate-limited and signed

Privacy by design

  • We do not sell or share your data with third parties
  • Contact and company data is workspace-private
  • Error monitoring excludes personally identifiable information
  • Session replay tools are configured with full text masking

AI & data access

  • AI features operate only on data within your workspace
  • Your data is never used to train third-party models
  • AI prompts and outputs are not stored beyond the session
  • See our AI Transparency page for full details

Responsible disclosure

  • We take security reports seriously and respond within 48 hours
  • Email security@gunimi.com for responsible disclosure
  • We do not pursue legal action against good-faith security researchers

Questions about security or compliance? security@gunimi.com