logo
Security & Trust

Your customers' conversations, handled properly

Gimiq handles transcripts, call recordings and customer records, so the controls around them matter as much as the features. This page sets out how data is encrypted, where it lives, who can reach it, and how long it is kept.

The controls that are always on

These are not enterprise upsells. They apply to every workspace on every plan, because a control you have to buy is a control most people won't have.

Encryption everywhere

TLS 1.2+ in transit and AES-256 at rest, applied uniformly to transcripts, call recordings, attachments and database backups.

Role-based access control

Permissions are granted by role, not by person. Agents, managers, admins and read-only viewers each see only what their role allows.

Single sign-on and MFA

SAML 2.0 and OIDC single sign-on with SCIM provisioning on enterprise plans, so joiners and leavers follow your identity provider.

Immutable audit logs

Every configuration change, data export, permission grant and AI action is recorded append-only, with actor, timestamp and parameters.

Automatic PII redaction

Card numbers, national IDs and other patterns you define are masked before storage, and voice payment capture uses a PCI-safe pause.

Configurable data residency

Choose the region your data is processed and stored in, with EU and US regions available and no cross-region replication by default.

What happens to your data

The questions a security review will ask, answered directly rather than buried in a policy PDF.

What we store

Conversation transcripts, call recordings where you enable them, customer records you sync, knowledge base content, and the audit log.

How long we keep it

Retention windows are set per data type and per queue. When a window closes, deletion runs automatically rather than on request.

Who can reach it

Your team, via the roles you grant. Gimiq staff access is break-glass only, requires an approved ticket, and is logged and time-limited.

What trains the models

Your conversations are not used to train shared foundation models. Your indexed content grounds answers for your workspace only.

Where it flows

Subprocessors are documented, and each integration you enable is scoped to the specific data it needs rather than blanket access.

Deletion on request

A subject deletion request removes the individual across transcripts, recordings, tickets and search indexes in a single operation.

Reporting a vulnerability

If you believe you have found a security issue, email support@gimiq.co with “security” in the subject line. We acknowledge reports within one business day and will agree a coordinated disclosure timeline with you. Please test only against your own workspace — never against another customer's data.

For DPAs, subprocessor lists, penetration test summaries or completed security questionnaires, contact our team.

Security questions

Still deciding? Talk to our team or browse the full FAQ.

Bring your security review

We would rather answer the hard questions before you sign than after. Send us your questionnaire and we will work through it.