Trust Center
For the champion - the church
Security Statement
Built with Protection in Mind
At Gloo, protecting customer data is fundamental to how we design and operate our products. Each offering is developed with security and privacy as core principles, aligning with industry-recognized frameworks and best practices. Through a combination of technical controls and organizational policies, we design products to help keep your data secure, so you can focus on your goals.
What You Can Expect
Data Encryption
We encrypt data in transit and at rest using industry standards
(TLS 1.2+ and AES-256), helping ensure your information is protected against unauthorized access.
Secure Infrastructure
Our services are hosted on leading cloud providers that employ layered physical, network, and operational security controls. These environments are designed to meet or exceed strict regulatory and compliance requirements.
Access Controls
Access to customer data is restricted to authorized personnel, governed by role-based permissions, strong authentication measures, and periodic access reviews, including controls over AI technologies and agents.
Organizational Safeguards
All Gloo employees undergo background checks (where permitted by law), as well as recurring privacy and security training. We maintain clear policies on data handling, security responsibilities, and vendor risk management to maintain and continuously advance a secure posture.
Resilience & Backup
Data is backed up regularly, with tested business continuity and disaster recovery plans to support service resilience and minimize downtime in the event of an incident.
Testing & Monitoring
We continuously monitor our systems for anomalies and threats, with dedicated alerting and response protocols. Regular internal audits, vulnerability assessments, and third-party penetration tests validate our security posture.
AI Security & Governance
Gloo's AI-enabled products are built under a dedicated AI governance program designed with reference to the NIST AI Risk Management Framework and ISO 42001. We assess AI-specific risks across the full product lifecycle, from training data integrity and model behavior to deployment and monitoring.
AI technologies used by personnel and within our products are subject to the same access controls, encryption, logging, and incident response standards as the rest of our technology environment, with additional controls for adversarial robustness and human oversight of high-stakes decisions.
Compliance & Best Practices
Our security program is designed with reference to industry standards such as the AICPA Trust Services Criteria, the NIST Cybersecurity Framework 2.0, the NIST AI Risk Management Framework 1.0, ISO/IEC 27001, and ISO 42001. We also incorporate privacy practices aligned to modern data protection regulations.
Need More Details?
If your organization requires additional assurances or a detailed look into Gloo’s security program, our security team is ready to collaborate with you (support@gloo.us).
Last Revised: Jul 31, 2026