Snapshot 40755
Normalized text
Scripts and page chrome removed; this is what change detection compares.
Security practices
This page summarizes how Gleap protects customer data. The contractually binding version of these commitments is the technical and organizational measures annex (Annex 6.1) of our Data Processing Addendum. Gleap is SOC 2 Type II audited for the Security trust services category. The latest report was issued on August 27, 2026 and covers April 1 to June 30, 2026. The report defines the audited systems and period; availability of a new hosting region does not itself establish that the region was included in that audit. Request the report via [email protected].
Infrastructure & hosting
Gleap’s EU infrastructure runs in the European Union (Frankfurt) on DigitalOcean, our main cloud provider, with additional providers listed in the sub-processor schedule.
The EU production MongoDB database is hosted through DigitalOcean Managed Databases in Frankfurt, Germany.
Gleap supports US data residency on DigitalOcean NYC3 (New York, United States). See the data residency guide for the scope of regional hosting and provider processing outside the selected region.
Cloudflare provides static file hosting for files uploaded through the Gleap widget and dashboard, such as screenshots and attachments, which may contain personal data, and video-call infrastructure. Cloudflare is a sub-processor; see our sub-processors page.
Current availability and incident updates are published on our status page.
Customer databases and their backups stay in the selected EU or US region. Uploaded files are stored with Cloudflare in separate storage for each region and are delivered through Cloudflare’s global network. AI features send requests to each provider’s default API endpoint from both regions; the one exception is xAI (Grok), which US accounts reach through xAI’s US endpoint. AI processing can therefore take place outside your hosting region, including in the United States. Provider operations and onward transfers remain subject to the sub-processor disclosures and DPA.
Encryption & data protection
Per our DPA’s technical and organizational measures (Art. 32 GDPR):
Encryption and pseudonymization of personal data.
Customer databases, backups, and uploaded files are encrypted at rest.
Data is encrypted in transit using TLS 1.2 or higher between your users, our SDKs, and our infrastructure.
Separation control: data collected for different purposes is processed separately; customer workspaces are logically isolated.
Access & organizational controls
Access controls on data processing systems: no unauthorized access, no unauthorized system use, and no unauthorized reading, copying, modification, or removal within the system.
Multi-factor authentication (MFA) is required for all systems and applications used by the Gleap team.
Staff access permissions are reviewed quarterly.
Personal devices are prohibited. Work from home is permitted through Gleap’s VPN using company-managed devices.
Transfer and input controls: no unauthorized access during electronic transmission, and traceability of whether and by whom personal data was entered, modified, or removed.
All personnel are bound to confidentiality; data protection responsibilities are anchored with Gleap’s data protection contact (Lukas Böhler, [email protected]).
A data protection management system provides regular review, assessment, and evaluation of the effectiveness of these measures, alongside privacy-friendly default settings.
Availability, resilience & recoverability
Availability control: protection against accidental or deliberate destruction or loss.
Resilience: systems are designed to tolerate and compensate for disruptions.
Recoverability: procedures ensure personal data and access to it can be restored.
DigitalOcean creates daily backups of the EU production MongoDB database. These backups are stored in Frankfurt, Germany, with a rolling seven-day retention window.
Full EU database restoration is tested every six months. US backups remain in the US; contact us for US-specific retention and restoration information.
Incident response & breach notification
Gleap operates an incident response management process for preparing, identifying, and reporting security incidents.
Personal data breaches are reported to affected customers without undue delay after becoming aware (DPA clause 9.1), with a description of the breach, affected data categories, a point of contact, and the measures taken or proposed. Information can follow in phases as it becomes available. This supports customers’ own notification duties under GDPR, DORA and similar rules.
Breach reporting contact: [email protected]. Service incidents are additionally published on the status page.
Product privacy controls
What Gleap’s SDKs capture, and how you can limit the data that reaches us:
Web session replay masking: the JavaScript SDK masks password inputs by default. Other input values are recorded unless you mask them. To mask every input, call Gleap.setReplayOptions({ maskAllInputs: true }) before initializing Gleap. Add the rr-mask class to mask an element’s text, or rr-block to leave an element out of the replay. In screenshots, the rr-mask class masks input values. See privacy controls in our docs.
App replays: in iOS and Android apps, including apps built with Flutter, React Native or Capacitor, replays are screenshots of the app taken at intervals. The mobile SDKs have no masking option, so anything visible on screen can appear in a replay.
Content Security Policy guidance for embedding the widget is documented here.
AI features are optional. Administrators can disable individual AI features, and account-level AI availability is governed by credit availability or the legacy AI usage setting. Contact us for help configuring AI restrictions; the providers involved are listed on the sub-processors page.
Reporting a vulnerability
If you believe you’ve found a security vulnerability in Gleap, email [email protected]. Reports go directly to the team responsible for security at Gleap, and we’ll respond as quickly as possible.