Security
How Gugen thinks about security and what we do today. A detailed security whitepaper is available on request under B2B contracts.
Policy
Gugen practices security-by-design to protect customer data and product integrity. We comply with applicable laws and continuously improve our posture.
Data Encryption
All traffic is encrypted with TLS 1.2 or above. Where data has to be stored, we use the encryption and key management our cloud vendors provide. We explain the arrangement for each engagement before you sign.
Access Control
Production access is limited on a least-privilege basis and uses multi-factor authentication. We explain the access design and log handling for each engagement before you sign.
AI Training Policy
We never use customer data — from the AX business, Makaseta, Gugen Lab, or any engagement — to train Gugen's general-purpose models. Usage is strictly limited to fulfilling the engagement.
Incident Response
Upon detecting an incident, we follow our runbook to assess impact and notify affected stakeholders promptly.
Retention & Deletion
After contract termination, customer data is securely deleted within the specified retention period, which is defined in the contract.
Sub-processors
Sub-processors for cloud, analytics and authentication are evaluated before use and covered by the contracts each case requires. We answer questions about which sub-processors we use on request.
Certifications
We hold no third-party certification at this time. We will pursue certification where a client’s requirements call for it.
Vulnerability Reports
Found a security issue? Please email info@gugenlab.com. We respond promptly to good-faith reports and thank responsible reporters.
Need more?
We answer security questions individually, and prepare the documents each engagement requires.
