Third Party Index

Snapshot 40739

Document
Trust center
URL
https://www.gleap.ai/trust
Fetched
HTTP status
200
Content type
text/html
Fetch mode
static
Size
158970 bytes
SHA-256 (raw)
16f0d2609ef755ce1cbea9dc64923c1560ec2b1308ee6e1623a0fbee90223c56
SHA-256 (normalized text)
03e9888381dc6ca2d9cdee7e2d44fe21b46595d972bf01ce2b361650bedcb905

Normalized text

Scripts and page chrome removed; this is what change detection compares.

Trust center
Security and compliance at Gleap
Gleap is SOC 2 Type II audited and GDPR (DSGVO) compliant, with EU or US data residency chosen at signup. Everything you need to assess Gleap as a vendor is on this page.
Compliance at a glance
SOC 2 Type II
Independently audited for the Security trust services category. The report specifies the systems and period covered. Request the current report by emailing [email protected].
GDPR (DSGVO)
GDPR-compliant processing with a public Data Processing Addendum, international-transfer safeguards for third-country transfers, and a documented sub-processor list.
EU and US data residency
Choose EU or US hosting at signup for your customer content. Review the residency scope and provider processing locations in our data residency guide.
DORA vendor readiness
Vendor information for financial entities regulated under DORA: Register of Information data, Article 30 mapping, and due-diligence support.
Encryption & security controls
Technical and organizational measures per Art. 32 GDPR: encryption, access controls, availability, resilience, and recoverability.
HIPAA and health data
Gleap does not publish a standard HIPAA Business Associate Agreement. Our DPA allows health data only when expressly agreed in writing. Contact [email protected] before processing protected health information.
Documents & resources
Everything a security or compliance review typically needs:
EU and US data residency: region selection, processing scope, international transfers and setup documentation.
Security practices: infrastructure, encryption, access controls, incident response, and product privacy controls.
Sub-processors: the third parties that process data on Gleap’s behalf, with locations and purposes.
DORA information for financial entities: Gleap’s role as an ICT third-party service provider under Regulation (EU) 2022/2554.
Privacy Policy: how Gleap collects, processes, and protects personal data.
Terms of Service: including our incorporated Data Processing Addendum.
Data Processing Addendum (PDF): our standard DPA with international-transfer provisions, technical and organizational measures, and the approved sub-processor annex. A copy signed by both parties is available via [email protected].
Imprint: legal entity information for Gleap GmbH.
Status page: current service status and incident updates.
SOC 2 Type II report: available under NDA on request. Email [email protected] and we’ll share the current report.
Trust FAQ
How do I get Gleap's SOC 2 Type II report?
Email [email protected]. We share the current SOC 2 Type II report under NDA with customers and qualified prospects.
Where is my data hosted?
Choose EU or US data residency when you sign up. Customer databases and their backups are hosted in the selected region, and uploaded files are stored in separate storage for each region. AI, email, integrations and other providers may process data outside that region. See our data residency guide and sub-processors page.
Is Gleap DORA compliant?
DORA regulates financial entities, not their software vendors, and no DORA certification exists for providers. Gleap supports your DORA assessment as an ICT third-party service provider: we provide Register of Information data, our DPA terms on sub-processors, breach notification, audits and data return, and documentation for your due diligence. Details on the DORA page.
Do you sign DPAs?
Our DPA is incorporated into our Terms of Service, so no signature is required. If your organization needs a copy signed by both parties, email [email protected]. To keep terms consistent we sign our standard DPA rather than customer-provided DPAs.
Can the AI features be disabled?
Administrators can turn off individual AI features. Account-level AI availability also depends on your AI credit balance or, on legacy plans, the AI usage setting. Stopping credit purchases does not stop AI processing while credits remain or automatic recharge is on. The AI providers are listed on the sub-processors page. Contact us to agree account-specific restrictions.
How do I report a security issue?
Email [email protected]. Reports go directly to the team responsible for security and data protection at Gleap.