Security
How we protect accounts, payments and files.
Last updated: 21 August 2026
1. Principles - Least privilege and role-based access - Encryption in transit (TLS) - We do not collect or store seller provider API keys at all; credentials used for AI fulfilment are operator-held environment secrets and are never written to the application database - No storage of card PANs or KYC identity documents on GigBlend servers - Signed webhooks and idempotent payment handling - Order-scoped file access checks - Audit logging for high-risk admin actions
2. Product controls - Session security and optional MFA - Rate limiting on sensitive endpoints - Malware scan integration points for uploads - Executable file-type blocks in messaging - Off-platform payment/contact detection for trust & safety
3. Infrastructure Production targets UK/EEA regions where available. Backups and restore procedures are documented for operators.
4. Vulnerability disclosure Email support@gig-blend.com with a good-faith report. Please do not access other users’ data or disrupt service. We will acknowledge credible reports.
5. Incidents We investigate and, where personal data is affected, notify parties as required by UK GDPR.
Questions?
Privacy: privacy@gig-blend.com · Legal: legal@gig-blend.com · See also Contact & company information.