Security

Your data is safe with us

Security isn't an afterthought at Gryphin. Here's exactly how we protect your team's work — and, just as importantly, what we haven't built yet.

256-bit encryption
GDPR aligned

How we protect your data

We implement multiple layers of security to ensure your data remains private and secure.

Encryption at Rest & In Transit

All data is encrypted using AES-256 at rest and TLS 1.3 in transit. Your information is protected at every stage.

Managed Infrastructure

Gryphin runs on Vercel with a Supabase-managed Postgres database and Cloudflare in front, so backups and platform patching are handled by providers who do it at scale.

Authentication & Access Control

Two-factor authentication via TOTP authenticator apps, plus role-based access controls that govern what each member can do in a workspace.

Row Level Security

Postgres Row Level Security policies enforce workspace boundaries on every query, so a request can only reach data the account already owns.

Privacy by Design

We collect only what we need to run the product, and you can delete your data at any time. Your data is never used to train AI models.

Secure Development

Every change goes through code review, and automated dependency scanning flags known vulnerabilities in the packages we rely on.

Our security practices

We follow industry best practices and continuously improve our security posture to protect your data.

Encryption at rest (AES-256) and in transit (TLS 1.3)
Postgres Row Level Security for workspace isolation
Two-factor authentication (TOTP) on any account
Automated dependency vulnerability scanning
Code review on every change
Error and performance monitoring via Sentry
Cloudflare Turnstile bot protection on public forms
Secure API authentication with rate limiting
Incident response and breach notification procedures
Principle of least privilege access

Compliance & Certifications

NZ Privacy Act 2020

Gryphin is built by Laika Dynamics Ltd, a New Zealand company operating under the Information Privacy Principles.

GDPR Aligned

We follow GDPR principles for EU users — data minimisation, access and erasure. A formal review is underway.

Data Processing Terms

Contact us about data processing terms and we will work through your requirements with you.

Activity History

Board and card activity is recorded so you can see what changed, when, and who changed it.

Certifications

We are not SOC 2 or ISO 27001 certified today. Both are on our roadmap and we will say so here when that changes.

Responsible Disclosure

We value the security community's efforts in helping keep Gryphin safe. If you believe you've found a security vulnerability in our platform, we encourage you to report it responsibly.

Please email security concerns to security@Gryphin.app. We aim to respond to all reports within 48 hours and will work with you to understand and resolve the issue.

Need enhanced security features?

SSO/SAML and SCIM provisioning are on our roadmap rather than available today. Tell us what your organisation needs and we'll be straight with you about timing.

Gryphin is built by Laika Dynamics Ltd, a New Zealand company. Last updated: July 2026. For a fuller breakdown of our sub-processors and compliance posture, see our Trust Center.