gimmefy
DBSSingtelUnileverVolvo
Start with 2,000 credits

Security & Privacy

Your Brand Data Is Not
Our Business Model.

Your data never trains AI models. 900+ row-level security policies guard every row, on every table. Two production regions, Frankfurt and Tokyo. And when we are not certified for something, this page says so.

Certified infrastructure

AWS: ISO 27001, SOC 1/2/3. Supabase: SOC 2 Type II

EU hosting

Frankfurt, Germany (eu-central-1) for EU and UK customers

GDPR

Processor DPA with SCCs, 72-hour breach notification

AES-256 · TLS

Encrypted at rest and in transit

SSO · MFA

SAML 2.0 single sign-on, TOTP MFA, org-wide enforcement

PCI DSS

Payments via Stripe (Level 1)

A note on certifications, up front. gimmefy does not hold its own SOC 2 or ISO 27001 certificate. The infrastructure we run on does: Amazon Web Services (ISO/IEC 27001, 27017, 27018, SOC 1/2/3, PCI DSS) and Supabase (SOC 2 Type II). Those attestations cover the data centres, network, hosts, storage encryption and the providers' own people and change control. How we configure those services, how our application enforces authorisation, how our staff reach production and how we ship code is ours, and it is described below and in the Data & Security document (PDF, v3.0).

Security at Every Step

1 Who Gets In (And Who Doesn't)

  • • Invite-only accounts. An organisation admin invites a user by work email; the user sets their own password through a time-limited link. No default or shared credentials. Email addresses are verified.
  • • Single sign-on: SAML 2.0 through our identity provider (Microsoft Entra ID, Okta, Google Workspace), configured per organisation and email domain. Google sign-in is also available.
  • • Multi-factor authentication via TOTP (Google Authenticator, Microsoft Authenticator, Authy, 1Password). Any user can turn it on. Org admins can make it mandatory and the platform blocks access until enrolment is complete.
  • • Removing a user takes effect immediately at the database layer, not just in the interface.

2 Your Data, Your Rules

  • • Your data is never used to train, fine-tune or evaluate any AI model. Not by us, and not by the providers we use (see section 5).
  • • We store only what the service needs: account data, authentication data and technical logs. We do not build profiles of your customers.
  • • Outputs download in open formats (DOCX, PDF, CSV, PNG, MP4) at any time. A full export of an organisation's content is provided on request.
  • • Deletion on request, confirmed in writing. After termination your content stays exportable for 30 days and is then permanently deleted.

3 Your Data Can't See Their Data

  • • 900+ row-level security policies inside the database. Row-level security is enabled on every table, not most of them.
  • • Every row carries partner, organisation and workspace identifiers, and the database checks them against the caller on every read and write. A bug in application code cannot return another tenant's rows.
  • • White-label partners are isolated from each other and from gimmefy's own tenants in exactly the same way.
  • • The isolation perimeter is checked with automated security advisors on every quarterly review.

4 Not Everyone Gets the Keys

  • • Organisation roles: Org Admin (users, settings, billing), Manager (day-to-day content and workspaces), Member (create and use).
  • • White-label partners hold a partner-level role for provisioning and support across the client organisations they host.
  • • Role changes are checked in the database, so nobody can escalate their own privileges through the API.
  • • Our own engineers: named individuals, least privilege, MFA on every production console, quarterly access review. Customer content is opened only to resolve a request you raised or an incident, and that access is logged.

5 What Happens When We Talk to the AI

The question enterprise security teams ask most, answered exactly.

  • • Sent per request: your prompt, the brand context relevant to that task (passages retrieved by semantic search, never the whole vault), files you attached to that request, and the thread history.
  • • Never sent: another tenant's data, your credentials, billing data, your user directory. Nothing goes to a provider unless a user picks a capability that uses it.
  • • Every provider is accessed through its commercial API. Anthropic, OpenAI and Google state in their terms that API data is not used to train their models.
  • • Retention after the request: Anthropic deletes within 30 days, OpenAI holds up to 30 days for abuse monitoring, Google holds 55 days for the Gemini API. Then it is gone.
  • • Zero data retention: we run on standard commercial terms today, so those windows apply. Enterprise and white-label clients who need ZDR can have it arranged with the providers that offer it, and their workspace restricted to those providers.
  • • Around 50 models from roughly 20 providers are live at any time. The current roster is in the product under AI Stack, and can be restricted to named providers per workspace.

6 Built on Certified Infrastructure. Configured by Us.

  • • Two production regions: Frankfurt, Germany (AWS eu-central-1) for EU and UK customers, and Tokyo, Japan (AWS ap-northeast-1) for Asia-Pacific. Your account lives in one and stays there.
  • • Database, authentication, file storage and 200+ edge functions run on Supabase (SOC 2 Type II) inside AWS (ISO 27001, SOC 1/2/3, PCI DSS). Media rendering on Google Cloud Run, in-region.
  • • The database is not reachable from the public internet. Every API call carries a short-lived, authenticated token.
  • • Daily backups with point-in-time recovery, retained in-region. AES-256 at rest, TLS 1.2+ in transit.
  • • Separate development, staging and production environments. No customer data outside production.

7 Continuous Protection

Our application layer defends against the common web vulnerabilities:

  • • Origin allow-listing on every backend function.
  • • HTML and SVG generated by models is sanitised with DOMPurify, and previews render inside sandboxed iframes.
  • • Protection against server-side request forgery on every function that fetches a URL.
  • • Input validation with type, size and length limits. Strict file-type allow-listing on uploads.
  • • Peer-reviewed pull requests, automated tests and a fixed promotion path (dev, main, staging, production) for every change, including every access-control policy.

Third-Party Subprocessors

Every third party that can receive customer data, what it gets, and where it processes. Nothing reaches an AI or data-collection provider unless a user chooses a capability that uses it.

Category Provider(s) Data shared Location
InfrastructureSupabase, Amazon Web ServicesAll platform data, encrypted at restFrankfurt or Tokyo, per your region
Media renderingGoogle Cloud (Cloud Run)Media being renderedFrankfurt (EU) · Singapore (APAC)
AI model providersAnthropic, OpenAI, Google, xAI, Perplexity, DeepSeek, BytePlus, Kuaishou, Moonshot, MiniMax, Zhipu, StepFun, Alibaba Cloud, Manus, fal.ai, OpenRouterThe request content described in section 5, only for capabilities the user invokesUS / global APIs, under SCCs in the DPA
Voice and avatarElevenLabs, HeyGenScripts and reference media for that requestUS / global
AI request tracingLangSmith (LangChain, Inc.)Prompts and outputs in traces, limited retention, engineering access onlyUnited States
Public web and social dataApify, Firecrawl, Tavily, BrowserlessSearch terms, brand names and URLs onlyUS / global
Transactional emailResendName and email addressUnited States
Payments (direct customers)StripePayment data only (PCI DSS Level 1)US / global
Business operationsGoogle Workspace, ZohoBusiness contact details and correspondenceGlobal

What's In Progress

Listed so nobody mistakes them for things we already do.

●

Independent penetration test SCHEDULING · Q4 2026

Third-party test of the production platform. Report available under NDA.

●

Web application firewall IN PROGRESS

AWS WAF managed rule sets and rate rules on the CloudFront distribution.

●

Cloud threat detection IN PROGRESS

Amazon GuardDuty on our AWS accounts.

●

Breached-password screening IN PROGRESS

Reject known-compromised passwords at sign-up and change, both regions.

●

Idle-session timeout and session dashboard PLANNED

See and revoke active sessions.

●

Customer-facing audit log PLANNED

A log of user and admin actions you can read yourself.

●

Self-service export and erasure PLANNED

Organisation-level export and deletion without raising a request.

●

Zero-data-retention agreements EVALUATING

Platform-wide ZDR with the providers that offer it.

●

Our own SOC 2 Type II EVALUATING

Decision after the penetration test.

The Boring Stuff We Do Religiously

Are you SOC 2 or ISO 27001 certified?
No. Our infrastructure providers are: AWS holds ISO 27001, SOC 1/2/3 and PCI DSS, and Supabase holds SOC 2 Type II. We share their reports under NDA. gimmefy's own controls are described on this page and in the Data & Security document, and we complete your security questionnaire.
Where is my data stored?
In the region your account is provisioned in. EU and UK customers are in Frankfurt (AWS eu-central-1): database, authentication, files and media rendering. Asia-Pacific customers are in Tokyo. Stored data does not leave your region. AI requests are processed transiently by the provider under the terms in section 5.
Do you train on my data?
No. gimmefy has no training pipeline. Providers are accessed through commercial APIs whose terms prohibit training on inputs and outputs. Anthropic, OpenAI and Google say so explicitly in their terms.
Exactly what leaves your systems when we use an AI feature?
The prompt, the brand context retrieved for that task, any file attached to that request, and the thread history, sent over TLS to the provider behind the model the user chose. The provider returns the output and keeps the exchange only within its abuse-monitoring window (30 days at Anthropic and OpenAI, 55 days at Google), then deletes it. Nothing from another tenant, and no credentials or billing data, is ever included.
Do you have zero-data-retention agreements with the AI providers?
Not yet. Standard commercial API terms apply today. For clients who need ZDR we will apply for it with the providers that offer it (Anthropic, OpenAI and Google do) and restrict the workspace to them.
Can we limit which AI providers our workspace uses?
Yes. Enterprise and white-label workspaces can be restricted to named providers. Anthropic, OpenAI and Google only is the usual request.
Are you NIS2 compliant?
NIS2 does not apply to gimmefy directly. It applies to organisations that are essential or important entities and requires them to manage supplier risk. We give you what that needs: a named security contact, 72-hour incident notification, documented risk management and secure development, a full sub-processor list, and a completed supplier questionnaire.
How do you handle SSO and MFA?
SAML 2.0 SSO (Microsoft Entra ID, Okta, Google Workspace) configured per organisation, plus Google sign-in. TOTP MFA for any user, compatible with Google Authenticator, Microsoft Authenticator, Authy and 1Password. Org admins can enforce it for every member.
Who at gimmefy can see our content?
Named engineers, with MFA, on a least-privilege basis, and only to resolve a support request you raise or an incident. Access is logged and reviewed quarterly.
Have you had a penetration test?
Not yet on the current platform. One is being scheduled for Q4 2026 and the report will be available under NDA. An earlier test covered a previous generation of the product, so we do not circulate it.
What happens if there is a breach?
We notify affected customers without undue delay and within 72 hours of becoming aware, with the information you need for your own regulatory notifications. Critical incidents escalate to the founder immediately and remediation starts within 24 hours.
Can I get a Data Processing Agreement (DPA)?
Yes. Our DPA covers GDPR Article 28 terms, EU Standard Contractual Clauses and the UK Addendum, the sub-processor list, 72-hour breach notification, deletion and audit cooperation. If you contract through a white-label partner, the partner is the controller or processor of record and gimmefy is the sub-processor. Ask at support@gimmefy.ai.
How do we export or delete our data, and what happens when we leave?
Outputs download in open formats at any time. Full organisation export and deletion are actioned on request. After termination, content stays exportable for 30 days and is then permanently deleted.
What if gimmefy is acquired or ceases trading?
Your agreement, including the deletion and export obligations, transfers with the business. Your files are in open formats and exportable at any time, so nothing depends on gimmefy continuing to exist.

The Full Document

Data & Security v3.0 (September 2026): shared-responsibility model, per-provider retention terms, confidentiality controls, sub-processor list with locations, and an honest roadmap. Built for security questionnaires (SIG, CAIQ, VSA) and legal review.