Security & trust
Your data is actually protected — not just on paper
We're a small, early-stage company. We don't have formal certifications yet (see why below) — but the technical protections are in place and running, not planned. Here's exactly what applies.
What we actually do
Concrete, already-implemented protections — not statements of intent.
Encryption in transit
All traffic runs over TLS 1.2 or newer. No unencrypted communication between your browser and our servers.
Encryption of sensitive data
Sensitive data (e.g. stored email passwords for integrations) is encrypted with AES-256-GCM in the database.
Passwords are hashed, never stored in plaintext
User passwords are hashed with BCrypt. Nobody at GothiaAI can see your password, not even for support.
Two-factor authentication
TOTP-based 2FA is available on every account, with an option for admins to require it organization-wide.
Two-layer isolation between customers
Every API call is validated against the right organization (tenant), and the database has its own protective layer (query filter) that prevents data leaking between customers — even in the event of an application bug.
Full audit log
Sensitive actions (logins, changes, deletions) are logged with who, what and when — traceable after the fact.
Automatic deletion under GDPR
Request account deletion and all data is automatically removed within 30 days. AI and notification logs are cleared on a rolling 90-day basis.
Your own data export, any time
You can download all your data (contacts, deals, tickets and more) as a file, whenever you want, without contacting us.
All data stays in the EU
Our production environment runs on Scaleway in France. No customer data leaves the EU for storage. Some AI requests (to Anthropic and, as a fallback, Ollama Cloud) are processed in the US in real time — nothing is stored with them and nothing is used to train their models. Full details in our sub-processor list.
Why no certifications (ISO 27001, SOC 2) yet?
Formal certifications take 6–12 months and require an external auditor — that's not a sign of weaker security, it's a sign of an early-stage company. We already follow ISO 27001-aligned practices (see above) and will pursue formal certification once customers ask for it, typically once you're a larger company with your own procurement requirements.
Legal documents
Full details in our formal documents: