We prioritize the security of your advertising and customer data. This document outlines our security architecture and practices.
Infrastructure & Hosting
Glimmio is hosted on Hostinger cloud infrastructure in Mumbai, India. Our deployment follows these practices:
- Network isolation: Customer data services are not exposed to the public internet.
- Encrypted connections: Certificates are renewed automatically and unencrypted requests are redirected to HTTPS.
- Restricted access: Inbound access is limited to the services required to operate and maintain Glimmio.
Data Encryption
- In Transit: All data transmitted between clients (browsers, APIs) and Glimmio is encrypted using TLS 1.3.
- At rest: Stored customer data and uploaded assets are protected by storage encryption.
- Credentials: OAuth tokens, API keys, and other sensitive credentials receive an additional layer of authenticated encryption, with encryption keys kept separately.
Authentication & Authorization
- Channel connections: Meta, Google, and Shopify connect through their official OAuth or managed-install flows. Access tokens are encrypted before storage and never shown in the browser. We never ask for your password.
- RBAC: Role-Based Access Control ensures users can only access data and perform actions appropriate for their role (Owner, Admin, Manager, Media Buyer).
- Session Management: Sessions are managed securely using HTTP-only, secure cookies with strict SameSite policies.
Vulnerability Management
- Dependency Scanning: We use automated tools to scan for known vulnerabilities in our dependencies (npm audit, Dependabot).
- Container Scanning: Docker images are scanned for vulnerabilities before deployment.
- Responsible Disclosure: We welcome security researchers to report vulnerabilities to help@glimmio.com.
AI Providers & Data Sharing
AI features send the minimum context needed for a request to OpenAI or Anthropic, depending on the service configured for Glimmio. Data handling depends on the account and controls in use. Glimmio does not promise zero retention or a specific service agreement unless that commitment is documented for the deployed account. See our Privacy Policy and Subprocessors page for more information.
Compliance
Glimmio acts as a Data Processor under GDPR and a Service Provider under CCPA. Formal third-party attestation is not yet in place; the controls described on this page are the ones implemented in the product today, and the security contact below will answer questionnaires directly.