Security
Security for regulated compliance records.
Compliance records are evidence, and some concern named individuals. This page describes the controls in place today. Detailed documentation is provided on request.
Security highlights
Your data is yours alone
Each organisation's records are kept separate and can never be seen by another.
A record nobody can rewrite
Every change is logged with who made it and when. The log cannot be edited or cleared, even by an administrator.
Two-step sign-in
Authenticator-app codes for every user, and strong password rules by default.
Access by role
Owner, compliance officer and member roles, plus four access levels for outside advisers.
Encrypted throughout
Encrypted in transit and at rest. Connection credentials are encrypted before they are stored.
Private documents
Evidence files are private to your workspace and open only through expiring links.
Locked once signed
Signed returns, scope determinations and exported packs cannot be changed afterwards.
AI that never decides
Where AI helps, it is labelled, every answer is sourced, and a person keeps the final say.
Data protection
- Separation
- Your organisation's records are held apart from every other customer's and cannot be read across that line.
- Verified
- That separation is tested automatically before every release.
- Least access
- Nothing in the browser can reach data the signed-in person is not allowed to see.
Encryption
- In transit
- All connections are encrypted.
- At rest
- Data and documents are encrypted by the hosting provider. Connection credentials for integrations are encrypted separately before storage.
- Passwords
- Never stored by GibComply in a readable form.
Authentication
- Two-step sign-in
- Authenticator-app codes, required before an integration can be connected.
- Passwords
- A 12-character minimum, checked against known breaches.
- Email confirmation
- New accounts confirm their address before signing in.
Role-based access
- Workspace roles
- Owner, compliance officer and member.
- Outside advisers
- View only, view and comment, edit, or sign-off. Advisers never see licences, suppliers, marketing or team data.
- One identity each
- A login is either an operator user or an outside adviser, never both.
Audit logging
- Complete
- Every create, edit and delete is recorded with who, when and what changed.
- Permanent
- The log cannot be edited or cleared by anyone, including the workspace owner.
- Locked records
- Signed returns, scope determinations and exported packs are frozen the moment they are created.
Hosting and backups
- Infrastructure
- Hosted on established cloud providers. Regions are confirmed in writing on request.
- Backups
- Managed by the hosting provider. Schedule and restore process provided on request.
- Monitoring
- Errors and abuse attempts are monitored and rate-limited.
GDPR and data retention
- Regime
- Personal data is processed under the Gibraltar GDPR and the Data Protection Act 2004.
- Data processing addendum
- Under review by a Gibraltar lawyer; published on the data processing page when complete.
- Retention
- Your records stay until you delete them. Retention on closure is agreed in your contract.
Security reviews and documentation
If your procurement process includes a security questionnaire, we will complete it and provide further detail on hosting, backups, data handling and the third parties we use. Read the Privacy Policy and the data processing page.
Bring your Gibraltar compliance into one system.
Obligations, evidence, responsibilities and reporting under the Gambling Act 2025, in a workspace your compliance officer, your board and your auditors can rely on.
