Legal & Policies

Security Policy

GATHWAYVersion 1.0 (Founder's Edition)
Effective Date: August 9, 2026

1. Purpose

This Security Policy explains GATHWAY's commitment to protecting the confidentiality, integrity, and availability of our platform and the information entrusted to us.

Our security objectives are to:

Protect user information.

Maintain secure services.

Prevent unauthorized access.

Detect and respond to security incidents.

Continuously improve our security practices.

This policy applies to all GATHWAY services, infrastructure, employees, contractors, and authorized service providers.

2. Security Principles

GATHWAY is guided by the following principles:

Security by Design

Privacy by Design

Least Privilege

Defense in Depth

Continuous Improvement

Responsible Disclosure

Risk-Based Decision Making

Security considerations are incorporated throughout the software development lifecycle.

3. Account Security

Users are encouraged to:

Choose strong, unique passwords.

Protect their login credentials.

Enable multi-factor authentication (where available).

Keep recovery information up to date.

Notify GATHWAY immediately if they suspect unauthorized access.

GATHWAY may require additional verification for sensitive account changes.

4. Authentication and Access Control

To protect user accounts and administrative systems, GATHWAY implements security measures such as:

Secure password hashing.

Session management.

Role-based access control (RBAC).

Authentication rate limiting.

Multi-factor authentication support where available.

Principle of least privilege for administrative access.

Administrative access is restricted to authorized personnel with a legitimate business need.

5. Encryption

Where appropriate, GATHWAY uses industry-standard encryption practices, including:

Encryption of data in transit using HTTPS/TLS.

Encryption of sensitive information at rest where supported by the underlying infrastructure.

Secure management of encryption keys and secrets.

We regularly review our cryptographic practices as standards evolve.

6. Infrastructure Security

Our infrastructure is designed with security in mind and may include:

Network segmentation.

Firewalls.

Secure cloud hosting.

Monitoring and logging.

Environment isolation (development, testing, production).

Regular software updates and patch management.

Access to production systems is restricted to authorized personnel.

7. Secure Development

Security is incorporated throughout the development lifecycle.

Practices may include:

Code reviews.

Automated testing.

Dependency vulnerability monitoring.

Static analysis where appropriate.

Security-focused design reviews.

Controlled deployment processes.

Security findings are prioritized based on risk.

8. Vulnerability Management

We actively work to identify, assess, and remediate security vulnerabilities.

This includes:

Monitoring for newly disclosed vulnerabilities.

Reviewing third-party dependencies.

Applying security updates where appropriate.

Prioritizing remediation based on severity and potential impact.

Critical vulnerabilities are addressed as quickly as reasonably practicable.

9. Incident Response

If a security incident occurs, GATHWAY will follow an incident response process that may include:

Identification.

Containment.

Investigation.

Eradication.

Recovery.

Post-incident review.

Where required by applicable law, affected users and relevant authorities will be notified.

10. Responsible Disclosure

We encourage security researchers and users to report suspected vulnerabilities responsibly.

Please include sufficient information to reproduce the issue.

Security reports should be sent to:

security@gathway.app