Security practices

This page summarizes how Gleap protects customer data. The contractually binding version of these commitments is the technical and organizational measures annex (Annex 6.1) of our Data Processing Addendum. Gleap is SOC 2 Type II audited for the Security trust services category. The latest report was issued on August 27, 2026 and covers April 1 to June 30, 2026. The report defines the audited systems and period; availability of a new hosting region does not itself establish that the region was included in that audit. Request the report via privacy@gleap.io.

Infrastructure & hosting

  • Gleap’s EU infrastructure runs in the European Union (Frankfurt) on DigitalOcean, our main cloud provider, with additional providers listed in the sub-processor schedule.
  • The EU production MongoDB database is hosted through DigitalOcean Managed Databases in Frankfurt, Germany.
  • Gleap supports US data residency on DigitalOcean NYC3 (New York, United States). See the data residency guide for the scope of regional hosting and provider processing outside the selected region.
  • Cloudflare provides static file hosting for files uploaded through the Gleap widget and dashboard — such as screenshots and attachments, which may contain personal data — and video-call infrastructure. Cloudflare is a sub-processor; see our sub-processors page.
  • Current availability and incident updates are published on our status page.

Customer databases, uploaded files and backups stay in the selected EU or US region. EU accounts use EU AI endpoints and US accounts use US AI endpoints. Separate provider operations and onward transfers remain subject to the sub-processor disclosures and DPA.

Encryption & data protection

Per our DPA’s technical and organizational measures (Art. 32 GDPR):

  • Encryption and pseudonymization of personal data.
  • Customer databases, backups, and uploaded files are encrypted at rest.
  • Data is encrypted in transit using TLS 1.2 or higher between your users, our SDKs, and our infrastructure.
  • Separation control: data collected for different purposes is processed separately; customer workspaces are logically isolated.

Access & organizational controls

  • Access controls on data processing systems: no unauthorized access, no unauthorized system use, and no unauthorized reading, copying, modification, or removal within the system.
  • Multi-factor authentication (MFA) is required for all systems and applications used by the Gleap team.
  • Staff access permissions are reviewed quarterly.
  • Personal devices are prohibited. Work from home is permitted through Gleap’s VPN using company-managed devices.
  • Transfer and input controls: no unauthorized access during electronic transmission, and traceability of whether and by whom personal data was entered, modified, or removed.
  • All personnel are bound to confidentiality; data protection responsibilities are anchored with Gleap’s data protection contact (Lukas Böhler, privacy@gleap.io).
  • A data protection management system provides regular review, assessment, and evaluation of the effectiveness of these measures, alongside privacy-friendly default settings.

Availability, resilience & recoverability

  • Availability control: protection against accidental or deliberate destruction or loss.
  • Resilience: systems are designed to tolerate and compensate for disruptions.
  • Recoverability: procedures ensure personal data and access to it can be restored.
  • DigitalOcean creates daily backups of the EU production MongoDB database. These backups are stored in Frankfurt, Germany, with a rolling seven-day retention window.
  • Full EU database restoration is tested every six months. US backups remain in the US; contact us for US-specific retention and restoration information.

Incident response & breach notification

  • Gleap operates an incident response management process for preparing, identifying, and reporting security incidents.
  • Personal data breaches are reported to affected customers without undue delay after becoming aware (per our DPA, §9), with a description of the breach, affected data categories, a point of contact, and the measures taken, so customers can meet their own regulatory notification deadlines (GDPR, DORA, and similar regimes).
  • Breach reporting contact: privacy@gleap.io. Service incidents are additionally published on the status page.

Product privacy controls

Gleap’s SDKs are built so you can minimize the data that reaches us in the first place:

  • Session replay masking: all inputs are masked by default (maskAllInputs), passwords are always masked, and any element can be excluded with the rr-mask class. See suppressing personal data in our docs.
  • Content Security Policy guidance for embedding the widget is documented here.
  • AI features are optional. Administrators can disable individual AI features, and account-level AI availability is governed by credit availability or the legacy AI usage setting. Contact us for help configuring AI restrictions; the providers involved are listed on the sub-processors page.

Reporting a vulnerability

If you believe you’ve found a security vulnerability in Gleap, email privacy@gleap.io. Reports go directly to the team responsible for security at Gleap, and we’ll respond as quickly as possible.