Enterprise-grade security

Your event data is sensitive. We protect it with the same rigour as financial services — encryption at every layer, strict access controls, and a complete audit trail.

GDPR

UK & EU compliant

TLS 1.3

Transit encryption

AES-256

At-rest encryption

SOC 2

In progress

Security, layer by layer

Every part of our stack is built with security as a first principle, not an afterthought.

Data Encryption

All data is encrypted at rest using AES-256 and in transit using TLS 1.3. Database backups are encrypted separately. Encryption keys are managed via a dedicated key management service with automatic rotation.

  • AES-256 encryption at rest
  • TLS 1.3 for all data in transit
  • Separate backup encryption
  • Automatic key rotation

Row-Level Access Controls

Gala Dock enforces strict row-level security (RLS) at the database layer — not just the application layer. This means even if an application-level check is bypassed, your data cannot be read or modified by another tenant's session.

  • Database-level RLS enforcement
  • Role-based access within teams
  • Granular permission scoping
  • Tenant isolation guaranteed
Coming Q4 2026

SOC 2 Type II — In Progress

We are currently working towards SOC 2 Type II certification. Our controls and processes are aligned with the SOC 2 Trust Service Criteria for Security, Availability and Confidentiality. Certification is expected in Q4 2026.

  • Controls aligned to TSC
  • Security & availability criteria
  • Third-party auditor engaged
  • Certification target: Q4 2026

GDPR Compliance

Gala Dock is built to comply with the UK GDPR and EU GDPR. All personal data is processed lawfully, stored in UK/EU data centres, and subject to strict data retention policies. We act as a Data Processor for your event data and provide a full Data Processing Agreement.

  • UK & EU GDPR compliant
  • UK/EU data centres only
  • Full DPA available
  • Right to erasure supported

Audit Logs

Every significant action in Gala Dock is recorded in a tamper-evident audit log. Know exactly who did what, when, and from which IP address. Audit logs are retained for 12 months on Growth plans and 36 months on Enterprise.

  • Immutable audit trail
  • IP address & device logging
  • User action attribution
  • 12–36 month retention

Infrastructure & Uptime

Gala Dock is hosted on enterprise-grade cloud infrastructure with automatic failover, daily backups, and a 99.9% uptime SLA on Growth and Enterprise plans. We use read replicas and CDN distribution to keep performance consistent globally.

  • 99.9% uptime SLA
  • Daily automated backups
  • Automatic failover
  • Global CDN distribution

Responsible disclosure

Found a vulnerability? We take security reports seriously and respond within 48 hours. Please report issues to security@galadock.com. We do not pursue legal action against good-faith researchers.

Contact security team

Have a security question?

Our team is happy to walk you through our security posture, share our DPA, or arrange a technical review for enterprise customers.

Get in touch