Security and privacy at Gotavi

Security is at the heart of what we do—helping our customers improve their business operations and compliance starts with protecting our own environment.

Security Governance

Our security and privacy initiatives establish robust policies and controls, continuously monitor compliance, and protect our services.

01. Least Privilege

Access is strictly limited to only those with a legitimate, verified business need and granted based on the principle of least privilege.

02. Defense in Depth

Security controls are implemented, layered, and verified across all enterprise dimensions according to the principle of defense-in-depth.

03. Continuous Evolution

Our controls mature iteratively across improved effectiveness, robust auditability, automated monitoring, and decreased user friction.

Data Protection

We act as trustworthy stewards of all sensitive operations and business data.

Data at Rest
All datastores containing customer records and cloud storage buckets are encrypted at rest using strong, industry-standard cryptographic algorithms. Additionally, sensitive personal or business identifiers are secured with application-level, field-level encryption prior to database storage.
Data in Transit
Gotavi enforces secure, modern transport encryption protocols (TLS 1.2 or higher) everywhere data is transmitted over public or potentially insecure networks. We leverage secure network configurations, strict transport policies, and cryptographically verified programmatic channels to maximize in-transit integrity.
Secret & Key Management
Encryption keys are managed securely through cloud key management systems featuring isolated hardware security modules (HSMs). Application secrets, database tokens, and API credentials are kept encrypted in isolated vault environments, injected in-memory strictly during initialization bootup.
Identity & Access Management
We secure identity and resource access using secure cloud identity providers and multi-factor authentication (MFA). Staff are granted system access strictly aligned with their organizational roles, with automated deprovisioning policies in place.

Product & Development Security

Ensuring security at every phase of our software development lifecycle.

Secure SDLC & Code Reviews

All application code, programmatic configurations, and infrastructure-as-code adjustments are subject to peer review. Deployments pass through automated pipelines containing continuous testing boundaries before reaching isolated staging and production environments.

Vulnerability Scanning

We require comprehensive vulnerability scanning at key stages of our software supply chain, including static application security testing (SAST) of pull requests, software composition analysis (SCA) to identify third-party dependency risks, and continuous infrastructure configuration checks.

Isolated Environments

Our staging, build, and production perimeters are fully isolated logically, with network segregation protecting backend database layers from direct external connections, and firewalls preventing unnecessary traffic.

Enterprise Security & Data Privacy

Striving to be excellent, compliant, and secure partners for our customers.

Endpoint & Device Security
Corporate devices are centrally managed, equipped with secure configurations (such as disk encryption and automatic updates), and monitored. Remote access is protected utilizing secure virtual private network (VPN) tunnels.
Incident Response & Backups
Gotavi maintains a documented Incident Response plan. Our database architectures run in resilient high-availability configurations with encrypted, automated daily backup policies. We conduct disaster recovery and system restoration evaluations periodically.
Regulatory Compliance & Partners
Gotavi uses a risk-based approach to secure vendor integrations. All credit card and bank transactions are fully vaulted and processed strictly through PCI-DSS Level 1 compliant payment partners, keeping Gotavi's environment out of PCI scope (SAQ-A alignment).
AI Trust & Private Models
Programmatic and Model Context Protocol (MCP) integrations are verified under secure, token-bound endpoints. Gotavi's workflow models and tools execute strictly inside our private cloud compute boundaries. Customer data, operational inputs, and model queries are never transmitted to third-party public AI APIs.

Continuous Security & Monitoring

Gotavi partners with Vanta to continuously monitor our cloud infrastructure, identity systems, and secure configurations. Our policies are approved, reviewed, and actively enforced by our security team under the direction of our CTO & Tech Co-founder.

Vanta Monitored SOC 2 Aligned