Skip to content
BehindGate

Trust Center

Security, privacy, and compliance

Everything a security review needs, in one place: how the service is built and operated, the legal documents every customer accepts, and where we stand on certifications.

How the service is protected

Hosted in the EU

Customer content and personal data are stored in AWS eu-west-1 (Ireland). Content delivery runs at AWS edge locations, and the few CloudFront supporting services that must live in us-east-1 handle request data in transit only.

Fail-closed access

Every request for published content is verified at the edge before anything is served. If a session cannot be verified, the request is denied. Content is never served anonymously.

You choose how viewers sign in

Production customers connect their own Microsoft Entra ID, Google Workspace, or OIDC provider, so access follows their directory and offboarding there ends access here. Email one-time codes are also available, mainly for trials and evaluation: you allow a domain, individual addresses, or both. Neither method requires a viewer directory in BehindGate.

Encryption everywhere

TLS 1.2 or later in transit, AWS managed encryption at rest. Signing keys and IdP secrets live in a managed secrets service, are rotated, and never appear in logs.

Separated trust planes

Viewer authentication, customer administration, and our internal operator console run on separate systems with separate credentials and no shared tokens.

Least privilege operations

Production access is limited to named staff behind multi factor authentication and is logged. Staff do not view customer content in the ordinary course of operating the service.

Compliance

GDPR

A Data Processing Agreement is incorporated into the Terms for every account, with a published sub-processor list, 48 hour breach notification, and EU data residency. It sets out our obligations as your processor. You remain the controller for the personal data you put into the service.

SOC 2 Planned

We intend to pursue a SOC 2 report. Until it is available, our security practices are documented here and in the DPA, and we answer written security questionnaires.

ISO 27001 Planned

Certification is on our roadmap. We build and operate the service against the controls now so that certification confirms existing practice rather than changing it.

Legal documents

These documents form the contractual framework for every BehindGate account and are accepted at sign-up. Each document states the plans and situations it applies to: for example, the Data Processing Agreement applies to every account, while the Service Level Agreement applies to paid plans. Enterprise customers may have a separate written agreement that takes precedence where it conflicts. Changes to commercial terms apply from the next billing period after 30 days email notice; changes required by law, an authority, or a security risk can take effect sooner.

Incidents and reporting

Incident communication

Account administrators are informed of incidents and scheduled maintenance by email. A public status page is planned.

Report a vulnerability

Email security@behindgate.com. We acknowledge reports within two business days and do not pursue good faith researchers.

Security questionnaires

Send written questionnaires and DPA countersignature requests to legal@behindgate.com.