Skip to content
GibComply

Security

Security for regulated compliance records.

Compliance records are evidence, and some concern named individuals. This page describes the controls in place today. Detailed documentation is provided on request.

Security highlights

Your data is yours alone

Each organisation's records are kept separate and can never be seen by another.

A record nobody can rewrite

Every change is logged with who made it and when. The log cannot be edited or cleared, even by an administrator.

Two-step sign-in

Authenticator-app codes for every user, and strong password rules by default.

Access by role

Owner, compliance officer and member roles, plus four access levels for outside advisers.

Encrypted throughout

Encrypted in transit and at rest. Connection credentials are encrypted before they are stored.

Private documents

Evidence files are private to your workspace and open only through expiring links.

Locked once signed

Signed returns, scope determinations and exported packs cannot be changed afterwards.

AI that never decides

Where AI helps, it is labelled, every answer is sourced, and a person keeps the final say.

Data protection

Separation
Your organisation's records are held apart from every other customer's and cannot be read across that line.
Verified
That separation is tested automatically before every release.
Least access
Nothing in the browser can reach data the signed-in person is not allowed to see.

Encryption

In transit
All connections are encrypted.
At rest
Data and documents are encrypted by the hosting provider. Connection credentials for integrations are encrypted separately before storage.
Passwords
Never stored by GibComply in a readable form.

Authentication

Two-step sign-in
Authenticator-app codes, required before an integration can be connected.
Passwords
A 12-character minimum, checked against known breaches.
Email confirmation
New accounts confirm their address before signing in.

Role-based access

Workspace roles
Owner, compliance officer and member.
Outside advisers
View only, view and comment, edit, or sign-off. Advisers never see licences, suppliers, marketing or team data.
One identity each
A login is either an operator user or an outside adviser, never both.

Audit logging

Complete
Every create, edit and delete is recorded with who, when and what changed.
Permanent
The log cannot be edited or cleared by anyone, including the workspace owner.
Locked records
Signed returns, scope determinations and exported packs are frozen the moment they are created.

Hosting and backups

Infrastructure
Hosted on established cloud providers. Regions are confirmed in writing on request.
Backups
Managed by the hosting provider. Schedule and restore process provided on request.
Monitoring
Errors and abuse attempts are monitored and rate-limited.

GDPR and data retention

Regime
Personal data is processed under the Gibraltar GDPR and the Data Protection Act 2004.
Data processing addendum
Under review by a Gibraltar lawyer; published on the data processing page when complete.
Retention
Your records stay until you delete them. Retention on closure is agreed in your contract.

Security reviews and documentation

If your procurement process includes a security questionnaire, we will complete it and provide further detail on hosting, backups, data handling and the third parties we use. Read the Privacy Policy and the data processing page.

Bring your Gibraltar compliance into one system.

Obligations, evidence, responsibilities and reporting under the Gambling Act 2025, in a workspace your compliance officer, your board and your auditors can rely on.