How we protect your data and maintain system integrity
GlyphNet is built with security as a foundational principle. We employ defense-in-depth strategies, encrypt all data at rest and in transit, and undergo regular third-party security assessments to ensure your data remains protected.
Annual audit covering security, availability, processing integrity, confidentiality, and privacy.
Full compliance with EU data protection regulations including data portability and right to erasure.
California Consumer Privacy Act compliance with opt-out mechanisms and data access requests.
Enterprise plans include BAA agreements for healthcare applications handling PHI.
Upon account deletion, all personal data is permanently removed within 30 days. Request deletion via privacy@glyphnet.io.
| Layer | Standard | Details |
|---|---|---|
| In Transit | TLS 1.3 | All API communication, HSTS enabled |
| At Rest | AES-256 | Database, backups, all storage |
| API Keys | Argon2id | Hashed, never stored in plaintext |
| Secrets | KMS | AWS KMS for key management |
gn_live_ and gn_test_ prefixesWe welcome security researchers to report vulnerabilities responsibly.
Our incident response plan follows industry best practices:
For security concerns, vulnerability reports, or compliance inquiries:
Enterprise customers can request our SOC 2 report, penetration test summary, and security questionnaire responses via security@glyphnet.io.