Security
Last updated June 11, 2026
We take the security of your data seriously. This page summarizes how GrowthGlass protects your information. For privacy details, see our Privacy Policy.
Encryption
- All traffic is encrypted in transit over TLS (HTTPS).
- Sensitive credentials - including any AI provider keys you bring - are encrypted at rest using application-level encryption.
- Data at rest is stored on managed infrastructure with disk-level encryption.
Tenant isolation
The Service is multi-tenant. Every record is scoped to a workspace, and access is enforced on every request so one workspace can never read another's data.
Authentication & access
- Passwords are hashed; we never store them in plain text.
- Role-based access within a workspace (owner vs member) governs billing and administrative actions.
- Internal access to production is limited to personnel who need it and is logged.
Payments
Payments are handled by Stripe, a PCI-DSS Level 1 certified processor. We do not store full card numbers on our servers.
Subprocessors
We use a small set of vetted subprocessors to run the Service (AI providers, hosting, payments, email). They are listed in our Privacy Policy. If you bring your own AI keys, your AI requests go directly to the providers you choose.
Reliability & backups
The database is hosted on managed infrastructure with automated, regularly tested backups and point-in-time recovery.
Reporting a vulnerability
If you believe you've found a security issue, please email hello@growthglass.app with details. We investigate all reports and will work with you on responsible disclosure.
Compliance
We align our practices with industry standards and GDPR/CCPA principles. [State your current compliance status here - e.g. SOC 2 in progress - and remove this note once accurate.]