Trust Center
Security, privacy, and compliance
Everything a security review needs, in one place: how the service is built and operated, the legal documents every customer accepts, and where we stand on certifications.
How the service is protected
Hosted in the EU
Customer content and personal data are stored in AWS eu-west-1 (Ireland). Content delivery runs at AWS edge locations, and the few CloudFront supporting services that must live in us-east-1 handle request data in transit only.
Fail-closed access
Every request for published content is verified at the edge before anything is served. If a session cannot be verified, the request is denied. Content is never served anonymously.
You choose how viewers sign in
Production customers connect their own Microsoft Entra ID, Google Workspace, or OIDC provider, so access follows their directory and offboarding there ends access here. Email one-time codes are also available, mainly for trials and evaluation: you allow a domain, individual addresses, or both. Neither method requires a viewer directory in BehindGate.
Encryption everywhere
TLS 1.2 or later in transit, AWS managed encryption at rest. Signing keys and IdP secrets live in a managed secrets service, are rotated, and never appear in logs.
Separated trust planes
Viewer authentication, customer administration, and our internal operator console run on separate systems with separate credentials and no shared tokens.
Least privilege operations
Production access is limited to named staff behind multi factor authentication and is logged. Staff do not view customer content in the ordinary course of operating the service.
Compliance
A Data Processing Agreement is incorporated into the Terms for every account, with a published sub-processor list, 48 hour breach notification, and EU data residency. It sets out our obligations as your processor. You remain the controller for the personal data you put into the service.
We intend to pursue a SOC 2 report. Until it is available, our security practices are documented here and in the DPA, and we answer written security questionnaires.
Certification is on our roadmap. We build and operate the service against the controls now so that certification confirms existing practice rather than changing it.
Legal documents
These documents form the contractual framework for every BehindGate account and are accepted at sign-up. Each document states the plans and situations it applies to: for example, the Data Processing Agreement applies to every account, while the Service Level Agreement applies to paid plans. Enterprise customers may have a separate written agreement that takes precedence where it conflicts. Changes to commercial terms apply from the next billing period after 30 days email notice; changes required by law, an authority, or a security risk can take effect sooner.
-
Terms of Service
The agreement that governs every BehindGate account. Business customers only, accepted at sign-up.
Version 1.0, effective 1 September 2026
-
Acceptable Use and Fair Use Policy
What may be published through BehindGate, and the fair use limits that keep the service reliable for everyone.
Version 1.0, effective 1 September 2026
-
Privacy Policy
How Rouhee Group Ltd handles personal data of BehindGate account holders, website visitors, and the people who contact us.
Version 1.0, effective 1 September 2026
-
Data Processing Agreement
The GDPR Article 28 terms under which BehindGate processes personal data on behalf of every customer. Included in the Terms of Service on every plan.
Version 1.0, effective 1 September 2026
-
Sub-processor List
The third parties that process customer personal data on BehindGate's behalf, where they operate, and how you are notified of changes.
Version 1.0, effective 1 September 2026
-
Service Level Agreement
The monthly availability commitment for viewer access to published Apps, the service credits it carries, and what is excluded.
Version 1.0, effective 1 September 2026
Incidents and reporting
Incident communication
Account administrators are informed of incidents and scheduled maintenance by email. A public status page is planned.
Report a vulnerability
Email security@behindgate.com. We acknowledge reports within two business days and do not pursue good faith researchers.
Security questionnaires
Send written questionnaires and DPA countersignature requests to legal@behindgate.com.