Security
How the platform is protected, how your connected accounts are handled, and what to do if you find a problem.
1. In transit
Everything between your browser and the platform runs over HTTPS. Requests to the providers we use run over encrypted connections too.
2. Credentials and keys
API keys and connected account credentials are encrypted before they are stored. They are not held anywhere in plain text.
Passwords are stored as hashes. Nobody here can read your password, including us.
3. Connected accounts
Connections that only need to read data are read only, including the analytics connection. A read only connection cannot change anything in the account it is connected to.
Connections that can write to a profile are limited to the locations you have added.
4. Access inside the company
Access to production systems is limited to the people who need it to run the service, and it is removed when somebody no longer needs it.
5. Bulk actions
Actions that change many profiles at once show you exactly what will be written before anything is applied, keep the previous values, and record what changed. That is a safety feature as much as a convenience one.
6. If something goes wrong
If a problem affects your data we will tell you what happened, what was affected and what we did about it, without waiting to be asked.
7. Reporting a vulnerability
If you find a security problem, email support@gmbaudit.co with enough detail to reproduce it. Please do not test it against other people accounts or data. We will confirm we have received it and keep you updated.
Who you are dealing with
GMBAudit is operated by TOTOSLOCAL ONE PRIVATE LIMITED, Sky Privlion, 501, Nipania, Indore, Madhya Pradesh 452010, India. Email support@gmbaudit.co.