Gugen

Security

How Gugen thinks about security and what we do today. A detailed security whitepaper is available on request under B2B contracts.

  • Policy

    Gugen practices security-by-design to protect customer data and product integrity. We comply with applicable laws and continuously improve our posture.

  • Data Encryption

    All traffic is encrypted with TLS 1.2 or above. Where data has to be stored, we use the encryption and key management our cloud vendors provide. We explain the arrangement for each engagement before you sign.

  • Access Control

    Production access is limited on a least-privilege basis and uses multi-factor authentication. We explain the access design and log handling for each engagement before you sign.

  • AI Training Policy

    We never use customer data — from the AX business, Makaseta, Gugen Lab, or any engagement — to train Gugen's general-purpose models. Usage is strictly limited to fulfilling the engagement.

  • Incident Response

    Upon detecting an incident, we follow our runbook to assess impact and notify affected stakeholders promptly.

  • Retention & Deletion

    After contract termination, customer data is securely deleted within the specified retention period, which is defined in the contract.

  • Sub-processors

    Sub-processors for cloud, analytics and authentication are evaluated before use and covered by the contracts each case requires. We answer questions about which sub-processors we use on request.

  • Certifications

    We hold no third-party certification at this time. We will pursue certification where a client’s requirements call for it.

  • Vulnerability Reports

    Found a security issue? Please email info@gugenlab.com. We respond promptly to good-faith reports and thank responsible reporters.

Need more?

We answer security questions individually, and prepare the documents each engagement requires.