Skip to content
Security and due diligence

Verify the controls that matter before production use.

This page separates controls visible in the public website implementation from product-security evidence that must be supplied and reviewed during procurement. It does not claim a certification or independent assurance report.

Verified in this website

Public-site controls

These statements are bounded to the marketing website and its form worker. They are not evidence about an unaudited product environment.

HTTPS and transport policy

The public site redirects HTTP and www requests to the canonical HTTPS origin. The edge adds HSTS and a restrictive referrer policy.

Browser security headers

The deployed worker defines a Content Security Policy, frame restrictions, MIME-sniffing protection, and a permissions policy for the public website.

Form abuse controls

Public forms use same-origin checks, a honeypot, a short time trap, input-length limits, validation, and duplicate-submission controls before forwarding a lead.

Consent-gated analytics

Analytics is loaded only after an affirmative analytics-consent choice. Visitors can reopen cookie settings from the footer.

Procurement boundary

Request current evidence

Do not infer product controls from marketing copy. Security, privacy, legal, and procurement owners should review dated evidence and ensure the executed agreement matches the proposed configuration.

  • Current product architecture and data-flow diagram
  • Exact subprocessors, hosting regions, and data-residency options
  • Authentication, authorization, audit-log, and tenant-isolation evidence
  • Encryption, key-management, backup, recovery, and deletion evidence
  • Incident-response, vulnerability-management, and penetration-test evidence
  • Current certifications, attestations, insurance, and contractual commitments

Need a security review?

Send your scope, systems, data categories, jurisdictions, and required evidence. Do not send credentials, production data, or confidential records through the public contact form.

Email security@getgangly.com