Security measures
Updated 6 days ago
Gratona’s security programme covers access control, encryption, incident response, backups and secure disposal. These measures support our Data Processing Addendum.
Access and confidentiality
Our access policy requires named accounts, least-privilege access, approval of privileged access, periodic access reviews and timely removal of access when responsibilities change. Personnel authorised to handle customer data are subject to confidentiality obligations. Multi-factor authentication is required for supported privileged and administrative access.
Encryption and data handling
Our encryption policy requires TLS 1.2 or later for protected data in transit and AES-256 or a documented equivalent for confidential data at rest. Credentials and encryption keys are access-controlled. Data sharing is limited to authorised recipients, necessary information and approved encrypted channels.
Backups and recovery
Our backup policy requires daily full database backups, protected backup access and periodic restoration testing. Retention and deletion follow the applicable customer agreement and retention schedule. Internal recovery objectives do not constitute an uptime or recovery-time service-level agreement.
Incident response
We investigate suspected security incidents, take steps to contain and remedy them, and notify affected customers without undue delay after becoming aware of a personal data breach, as described in the Data Processing Addendum.
Assurance and updates
We are undertaking SOC 2 readiness work as part of the Gratona rebrand. Information about our security programme is available through our Trust Center.
These are programme requirements. The version and any service-specific measures incorporated into an accepted Data Processing Addendum govern the contractual commitments. Updates will not materially reduce the agreed overall protection of customer personal data.
For security and privacy questions, contact [email protected].