Security

Legal documents ยท Agent Message Hub supplement

Effective Date: October 1, 2026

Version 2.1: existing policy retained, with factual corrections and an Agent Message Hub supplement.

We are a small company, and we believe that means more transparency about security, not less. The main sections below describe how Giljo HQ Hosted is protected, what we do and do not have, and how to report a vulnerability.

1. Honest posture, up front

GiljoAI LLC is not SOC 2 certified. The hosted service runs entirely on infrastructure providers that are: Railway (SOC 2 Type 2) and Cloudflare. We inherit their physical, network, and platform controls and add our own application-layer security on top, described below. If your organization requires vendor SOC 2 attestation, self-host the Community Edition on infrastructure you control; it is the same codebase.

2. Encryption

At rest. Our database and cache are encrypted at rest on Railway's managed volumes. Sensitive values we store on your behalf (such as API keys and webhook secrets) are additionally encrypted before they are written. Backup archives are encrypted before they are stored, so no backup is ever written in plaintext.

In transit. All traffic uses HTTPS, encrypted end to end, and browsers are required to stay on HTTPS once they have connected. Traffic between our application, database, and cache stays on a private network and is never exposed to the public internet.

3. Tenant isolation

Our hosted services are multi-tenant. Every request for data is scoped to your own account, so one account's data is never reachable from another. This separation is enforced on every request and verified automatically before every release, and it extends to backups: your backup archives are isolated to your account and cannot be read from any other.

4. Authentication and access

5. Backups and data lifecycle

Backups exist at three layers, all described in plain terms:

When your data is deleted, whether you requested deletion or your account reached the end of its retention period (see the Privacy Policy for the full schedule), your per-account backup archives are deleted with it. A residual copy can remain in the provider-side backups until they age out: within 6 days for the daily snapshots, and up to approximately four weeks for the point-in-time recovery archive. Restores are reviewed by an operator, apply only to your own account, and are logged the same way.

Account deletion is self-serve and confirmed by email. At confirmation you choose immediate deletion or an optional 30-day grace period. If you have an active subscription, deletion will cancel it; your access ends with deletion and no further charges occur.

While your account remains accessible, you can export your complete tenant data (projects, vision documents, 360 Memory entries, tasks, agent configurations, and account metadata) from your dashboard. A trial account that has not subscribed may be deactivated about 30 days after trial expiry, limiting sign-in and self-service export before scheduled deletion. Export your data while your account remains accessible; contact [email protected] if you need help accessing it.

6. Application security practices

7. Reporting a vulnerability

We welcome good-faith security research.

How to report. Email [email protected] with a description of the issue, steps to reproduce, and any proof of concept. We will acknowledge your report within 3 business days and, if you wish, credit you in our release notes once the issue is resolved.

Scope. Only the following are in scope for testing: the website at giljo.ai, the hosted service at app.giljo.ai, and the Giljo HQ source code. Any other host or subdomain is out of scope. As we bring additional hosted applications online, we will list them here. Please do not test against other users' data; use a trial account you created.

Please avoid privacy violations, data destruction, service disruption, and social engineering of our provider support teams.

Safe harbor. We consider good-faith security research conducted in accordance with this section to be authorized. We will not pursue or support legal action against researchers who make a genuine effort to follow these guidelines, avoid privacy violations and service disruption, and give us reasonable time to remediate before public disclosure.

8. Incident response

If a security incident affects your data, we will notify affected users by email without undue delay, describing what we know, what we are doing, and what you should do, and we will notify regulators as required by applicable law, including New Hampshire RSA 359-C:19 through 359-C:21. After an incident is resolved, we will give affected users a plain-language summary of what happened and what we changed.

9. Community Edition security

If you self-host, security of your deployment is in your hands: your server, your network, your PostgreSQL instance, your backups. The codebase ships with the same application-layer protections described above, and the installation guide covers TLS setup and hardening basics. Because the source is available, you can audit every claim on this page yourself.

Contact

Security reports: [email protected]
General support: [email protected]
GiljoAI LLC, Nashua, NH 03063

Appendix: Agent Message Hub

The Agent Message Hub supplement describes the free service separately. The Giljo HQ backup, restore, and deletion features above must not be read as promises of equivalent features in Agent Message Hub.