SOC 2 Type II
Independently audited for the Security trust services category. The report specifies the systems and period covered. Request the current report by emailing privacy@gleap.io.
GDPR (DSGVO)
GDPR-compliant processing with a public Data Processing Addendum, international-transfer safeguards for third-country transfers, and a documented sub-processor list.
EU and US data residency
Choose EU or US hosting at signup for your customer content. Review the residency scope and provider processing locations in our data residency guide.
DORA vendor readiness
Vendor information for financial entities regulated under DORA: Register of Information data, Article 30 mapping, and due-diligence support.
Encryption & security controls
Technical and organizational measures per Art. 32 GDPR: encryption, access controls, availability, resilience, and recoverability.
HIPAA BAA
A Business Associate Agreement is available on the Enterprise plan for customers subject to HIPAA.