Security & SSO
GrackerAI is built to meet enterprise security requirements.
Compliance & Certifications
| Certification | Status |
|---|---|
| SOC 2 Type II | Active - annual audit |
| GDPR | EU data subject rights honoured |
| CCPA | California privacy rights honoured |
| ISO 27001 | In progress |
Request the latest SOC 2 report via security@gracker.ai.
SSO (SAML Single Sign-On)
SAML SSO is available on Scale and Enterprise plans.
Supported identity providers:
- Okta
- Microsoft Entra ID (formerly Azure AD)
- Google Workspace
- OneLogin
- Generic SAML 2.0 IdP
How to Set Up SSO
SSO configuration isn't a self-serve page in the app today - your GrackerAI account team sets it up with you:
- Contact sales@gracker.ai to start SSO setup for your workspace
- In your IdP, create a new SAML application
- Share the metadata URL your GrackerAI contact provides with your IdP configuration
- Map the standard attributes:
email,name,groups - Test with one user account before enforcing org-wide
- Once confirmed, your GrackerAI contact enables SSO enforcement to require SSO for all members
Test before enforcing. Enabling SSO enforcement before testing can lock users out. Always verify one non-admin account successfully logs in via SSO first.
SCIM Provisioning
Available alongside SSO on Scale and Enterprise plans.
SCIM auto-creates new GrackerAI accounts when users are added to your IdP group, and deactivates accounts when they're removed. This eliminates manual seat management for teams with frequent membership changes.
Data Encryption
| Layer | Standard |
|---|---|
| Data at rest | AES-256 |
| Data in transit | TLS 1.3 minimum |
| Database backups | Encrypted - rotated daily |
Access Controls
| Control | Details |
|---|---|
| Role-based access | Owner, Admin, Member - see Team Management |
| Session timeout | Configurable - default 24 hours |
| IP allowlisting | Available on Enterprise plans |
| Audit logs | Available on Scale and above - tracks all admin actions |
| Two-factor authentication | TOTP-based - strongly recommended for all users, required for Admins |
Vulnerability Reporting
To report a security vulnerability, email security@gracker.ai. PGP key available on request.
We follow coordinated disclosure with 90-day timelines before public disclosure.