Trust Center

Security and transparency, by design.

We build autonomous security systems to protect your business. Learn about our compliance posture, data isolation practices, and how we safeguard your telemetry and identity data.

99.99%

Uptime

Live

Architectural

Data isolation

Zero data crossover

SOC 2 Type II

Compliance

Audit-ready

Document vault

Self-service security documentation.

Review our posture in seconds. Gated documents unlock instantly with a click-to-sign NDA, so your procurement timeline never has to wait on an email thread.

Document Description Access
SOC 2 Type II report Full independent auditor's report covering security, confidentiality, and availability. Click-to-sign NDA
Penetration test executive summary Our latest third-party external penetration test results and remediation status. Click-to-sign NDA
Gideon CAIQ / Consensus Assessment Standardized answers to the Cloud Security Alliance (CSA) security questionnaire. Public download
Data Processing Agreement (DPA) Our standard DPA outlining how we comply with GDPR, CCPA, and global privacy standards. Public download

Security architecture

Three pillars enforce trust at every layer.

Trust is continuous—across every identity, every device, and every access decision.

Gideon trust architecture pillars Gideon's three trust pillars work together: Identity verifies the person, endpoint protection secures the device, and access controls govern every permission. Identity Passwordless access Device trust built in Endpoint protection Every device secure and current From setup through every update Access controls Every permission governed Before it becomes risk Every layer is enforced by architecture, not policy alone

Under the hood

Real-time security posture, not a static PDF.

Multi-tenant data isolation

We enforce logical tenant isolation at the database layer using PostgreSQL Row-Level Security (RLS) and strict tenant-scoped partitioning on our event bus. Cross-tenant data leakage is structurally impossible.

All customer data is encrypted in transit using TLS 1.3 with secure cipher suites and at rest using AES-256. Cryptographic keys are managed via hardware security modules (HSMs) with strict rotation policies.

Endpoint agent integrity

The Gideon device agent is a lightweight, natively compiled binary. It runs without heavy external runtimes (like Node.js, Python, or Electron), drastically reducing the local attack surface on your endpoints.

Every agent release is code-signed and verified by the host operating system's native endpoint protection before execution.

Identity & access control

We enforce hardware-bound, WebAuthn-based multi-factor authentication for all administrative access to our production environments.

Zero permanent administrative privileges exist. Engineers must request just-in-time (JIT), time-bound access, which is automatically revoked and logged to a tamper-evident audit pipeline.

Automated compliance

We simplify your next audit too.

Audit-ready evidence

Gideon is designed to produce immutable, audit-ready evidence for authentication, policy decisions, and lifecycle changes.

Continuous configuration tracking

Every policy update, device drift, and remediation event is logged. We transform raw system telemetry into a readable narrative, significantly reducing the manual effort required during your compliance reviews.

Security questionnaire fast-track

Have a custom security questionnaire?

Upload your standard security assessment (SIG, CAIQ, or custom spreadsheet). Our security operations team will cross-reference it against our architecture and return a fully completed copy to you within 48 hours.

Upload security questionnaire

Enterprise demo

See Gideon against your fleet model.

Bring team size, identity provider, endpoint stack, and procurement path. We will map package fit, rollout shape, and POC timing.

  • 14-day POC framework
  • Marketplace and private offer support
  • Security questionnaire routing

Request an enterprise demo