Trust & Security

Enterprise data security is the foundation GlooFloo is built on

GlooFloo protects organization data through system-level isolation, multi-layer authentication, and a full audit trail for every change.

Request a Security Review

Organization-level data isolation

Each organization’s data is fully isolated from other organizations at the system level, not just at the interface level. Any attempt to access another organization’s data is rejected without even revealing that the data exists.

Strong, multi-layer authentication

Authentication methods: two-factor authentication (MFA), passkeys, and enterprise single sign-on (SSO).

Identity management and sync: the SCIM protocol manages and automatically syncs user identities with your organization’s systems.

Full audit trail

Every significant change in a workspace is logged, with privileged administration actions recorded separately in a dedicated audit log.

Governed data export and legal deletion

Workspace data can be exported at any time, through protected export links that expire automatically. Before any final deletion, GlooFloo honors legal hold requirements so that data subject to regulatory retention is never deleted unintentionally.

Governed AI

GlooFloo’s AI assistant suggests actions based on project context, but no action runs without your team’s explicit approval, every suggestion goes through approval controls before it’s applied.

Where is data stored?

99% of data is stored outside Saudi Arabia by default. For government contracts, a full system implementation is carried out either on the government entity’s own servers or on local Saudi hosting, to keep data within the Kingdom.

Compliance roadmap

Planned · no audit has started

GlooFloo currently plans to pursue SOC 2 and ISO 27001 certifications, along with compliance with Saudi Arabia’s Personal Data Protection Law (PDPL).

Frequently asked questions

Is my organization’s data isolated from other customers?
Yes, each organization’s data is isolated so that its projects and information are only accessible to authorized users.
Does GlooFloo hold specific security certifications?
GlooFloo currently plans to pursue SOC 2 and ISO 27001 certifications, and compliance with Saudi PDPL. Follow this page for the latest status.
Is single sign-on (SSO) available for organizations?
Yes, fully supported, along with the SCIM protocol for identity syncing.
Can AI make changes without my approval?
No, any action the AI assistant suggests requires your team’s explicit approval before it’s applied.
Can I export my data at any time?
Yes, through secure export links that expire automatically to protect data in transit.