Who can use this?
- Security information is available to all Gallabox users.
- Roles: Admin role for security settings management
Gallabox takes security seriously — your customer data is encrypted, access is controlled, and we’re committed to protecting your information. This page covers our overall security posture, compliance, and how to report vulnerabilities.
Encryption
All data transmitted between Gallabox and your systems (web browsers, mobile apps, API integrations) is encrypted using TLS 1.2 or higher. Data stored in our databases and file storage is encrypted at rest using AES-256.
Data Residency
Gallabox is hosted on AWS and MongoDB Atlas. Backups are distributed across multiple zones, with a primary data center in the US. For customers with specific data residency requirements, contact Gallabox support to discuss options.Access Control
- Role-based access control (RBAC) — team members only have access to features and data relevant to their role
- Principle of least privilege — new team members start with minimal access and are granted more as needed
- 2FA enforcement — Admins can require all team members to enable two-factor authentication
Compliance
Gallabox holds a SOC 2 Type II attestation covering the Security, Availability, and Confidentiality Trust Services Criteria, for the period January 16, 2025 to January 15, 2026, with no exceptions noted. We renew it annually. As a data processor under GDPR, we offer a Data Processing Agreement with standard contractual clauses and a published sub-processor list. Our SOC 2 report, control summary, and security policies are available through our Trust Vault at trust.gallabox.com. The full report is shared under NDA. Learn more about our compliance →Reporting Security Issues
If you’ve found a security vulnerability in Gallabox:1
Don't report it in public channels
Email security@gallabox.com with details.
2
Include the following details
- Description of the vulnerability
- Steps to reproduce
- Potential impact
- Your contact details (for follow-up)
3
We'll acknowledge within 48 hours
We’ll acknowledge within 48 hours and work on a fix.
4
Credit after the fix
Once fixed, we’ll credit your account (if applicable) and credit the finding in our security acknowledgements page.
Security Best Practices for Your Team
- Enable 2FA — for yourself and all team members; enforce it team-wide under Settings → Workspace → Users, Teams and Roles
- Use strong passwords — use a password manager to generate and store them
- Limit integrations — only connect tools you actively use
- Review activity log — check Settings → Developer → Activity Log for unusual activity
Related Articles
- Compliance — SOC 2 Type II, GDPR, and requesting our reports
- Data Security — data storage, retention, and deletion
- Data Processing Agreement (DPA) — Gallabox as a data processor
- Sub-processors — third-party services Gallabox uses
- Account Security Overview — 2FA, activity log, IP restrictions