GlooFloo information and trust center
Security
GlooFloo uses layered application and operational controls without claiming certifications that have not been independently awarded.
Effective 21 July 2026 · Version 1.0
Application controls
Server-side tenant authorization, least-privilege roles, secure sessions, validation, rate limits, audit events, and guarded privileged access protect core workflows.
Data and operations
Secrets are separated from source code, provider credentials are encrypted where supported, backups and recovery are governed, and customer content is excluded from unnecessary telemetry.
Reporting
Send suspected vulnerabilities to security@gloofloo.com with safe reproduction details. Do not access other tenants, disrupt service, or expose customer data.