Skip to main content
Trust & Security

Security at GrackerAI

We take the security of your data seriously. Here's how we protect it.

Encryption in Transit

All data transmitted to and from GrackerAI is encrypted using TLS 1.2+. Our SSL configuration holds an A+ rating from Qualys SSL Labs.

Encryption at Rest

Data stored in our infrastructure is encrypted at rest using AES-256. Database backups are encrypted and stored in geographically distributed locations.

Access Controls

Role-based access controls (RBAC) restrict internal access to production systems. All access is logged and reviewed. We follow the principle of least privilege.

Uptime & Reliability

Our platform targets 99.5% monthly uptime. Infrastructure is hosted on AWS and DigitalOcean with Cloudflare for DDoS protection and edge security.

Sub-processor Vetting

We vet all third-party sub-processors for security and compliance. Key processors include Stripe (payments), Cloudflare (CDN/security), AWS, and Anthropic/OpenAI (AI APIs).

Monitoring & Logging

We continuously monitor for anomalous activity across our infrastructure. Security logs are retained for 90 days and reviewed regularly.

Compliance

  • GDPR: We are GDPR-compliant for EU/EEA users. See our Privacy Policy for full details including your data rights.
  • CCPA: We honour California Consumer Privacy Act rights for California residents.
  • SOC 2: We are working towards SOC 2 Type II certification. Contact us for our current security questionnaire.
  • Data Processing Agreements (DPA): Enterprise customers can request a DPA. Email [email protected].

Responsible Disclosure

We take vulnerability reports seriously. If you believe you've found a security vulnerability in GrackerAI, please report it responsibly:

  • Email: [email protected]
  • Please include a clear description, steps to reproduce, and potential impact.
  • We will acknowledge receipt within 48 hours and provide a timeline for resolution.
  • We request you do not publicly disclose the vulnerability until we have addressed it.

Security Questions?

For security reviews, vendor questionnaires, or DPA requests: