Security
Last updated: 15.09.2026
1. Security Overview
Customer data security is the foundation of Guardiso. As an ISMS platform, we apply the highest data protection standards at every level: from infrastructure through application to organizational processes.
2. Infrastructure
Guardiso is hosted with a European cloud provider holding ISO 27001, SOC 2 and HDS certifications, with data centres located in the European Union.
3. Data Residency
By default, we store all customer data in the European Union, in a data centre in Poland, and it is subject to GDPR. It leaves the EU only in the cases described in the list of subprocessors.
On Professional and Enterprise plans, you can choose another location within the European Union. Write to us and we will set it up together.
4. AI Data Flow
AI features (Guardiso Assistant, policy generation, risk analysis) are entirely optional. The platform works fully without them.
The AI model provider processes data only for the duration of a request. It does not store query content after processing and does not use it for model training. Transfer based on Standard Contractual Clauses (SCCs).
5. Authentication
Guardiso uses Google OAuth 2.0 and email sign-in (a one-time, time-limited login link) for user authentication. We do not store user passwords.
- Google OAuth 2.0: secure login without password storage
- Magic link: one-time login link delivered by email, valid for a limited time
- Sessions & CSRF protection: secure session management and protection against CSRF attacks
- Session tokens: HTTP-only cookies, Secure flag, SameSite=Lax
- SSO / SAML: available on Enterprise plan Enterprise
6. Application Security
The Guardiso application is built with security in mind at every stage of the software development lifecycle.
- OWASP Top 10: protection against the 10 most common web threats (XSS, injection, CSRF, etc.)
- Content Security Policy (CSP): strict CSP headers limiting external resource loading
- Security headers: X-Frame-Options, X-Content-Type-Options, HSTS, Referrer-Policy
- Input validation: schema validation at all system boundaries
- Parameterized queries: SQL injection protection at the query layer. Column and table names are checked against an allowlist and values are bound as parameters
- Organisation isolation: server-side data filtering so each organisation sees only its own data, additionally enforced by role-based access control (RBAC)
- Automated scanning: automated vulnerability, secret and code scanning on every change in the CI/CD pipeline
7. Reporting security vulnerabilities
We value cooperation with the security community. If you discover a vulnerability in Guardiso, we ask for responsible disclosure.
Scope
- *.guardiso.com
How to Report
Send your report to: security@guardiso.com
Include in your report:
- Description of the vulnerability and reproduction steps (PoC)
- Potential impact
- Suggested fix (optional)
Response Time
We do not pay for reports. We value them and credit researchers by name if they wish.
Safe Harbor
We will not pursue legal action against security researchers who act in good faith and follow these guidelines:
- Do not exfiltrate customer data
- Do not disrupt service availability
- Allow us reasonable time to fix before public disclosure
Out of Scope
- Social engineering (phishing, vishing)
- DoS / DDoS attacks
- Physical attacks on infrastructure
- Vulnerabilities in third-party software (e.g., browsers)
- Missing best practices that do not lead to a specific attack
8. Compliance & Certifications
9. Jurisdiction of the infrastructure and access by third-country authorities
The ICT infrastructure on which we process customer data, that is to say the application servers, the database, the file storage and the vault holding the encryption keys, is located in Poland, in the Warsaw region, at the provider Scaleway, S.A.S., which is established in France. The infrastructure is subject to Polish law and to the law of the European Union, and its provider is additionally subject to French law. Customer data does not leave the European Economic Area other than in the cases identified in the list of subprocessors.
Contractual measures
A request from a public authority, a court, a prosecutor or a security service is not acted upon automatically. Before any disclosure we check whether the request comes from an entity entitled to make it and whether it has been properly served, whether it states a legal basis and the scope of the data requested, and we limit any disclosure strictly to the data covered by the request.
We notify the customer of a request received without undue delay, no later than within forty-eight hours of receiving it and before the data is disclosed, so that the customer can pursue legal remedies. Where a provision of law prohibits us from informing the customer, we withhold notification only to the extent and for the time covered by the prohibition, we make reasonable efforts to have it lifted or narrowed, and we notify the customer without undue delay once the prohibition ends.
A judgment of a court of a third country and a decision of an administrative authority of a third country requiring the transfer or disclosure of personal data may be given effect only where they are based on an international agreement in force, in accordance with Article 48 of Regulation (EU) 2016/679. We do not act on such requests outside that route. We impose the same obligation on our subprocessors by contract.
Organisational measures
We have not granted and do not grant any authority or security service permanent, direct or automated access to customer data. Access by our personnel to a customer’s data requires a request stating the scope, the duration and the reasons, together with the customer’s approval; it is time-limited and recorded in a log. Emergency access is permitted only in the event of an actual security incident and is subject to notification of the customer within seven days.
Technical measures
The personal data of each organisation is encrypted with its own key. That key may be deleted only by the owner of the customer’s organisation. Once the key has been deleted, the data encrypted with it is unreadable to us as well, and therefore cannot be disclosed to anyone in readable form.
10. Contact
If you have questions about Guardiso security:
- Security reports: security@guardiso.com
- General inquiries: contact@guardiso.com
See also: