ISO 27001:2022
activeThe international standard for information security management
ISMS in place, aligned with the latest version of the standard
Security and compliance
The Gamfi platform processes employee data and sales results, so before you roll it out your security team, IT and legal will review us. We have gathered here the practices, documents and answers they usually need to close that review.
Where the data sits
Microsoft Azure, EEA
Data centres within the European Economic Area.
Encryption
AES-256 and TLS 1.2/1.3
Where the data is stored, and in transit to the browser.
Management system
ISO/IEC 27001:2022
An information security management system aligned with the standard.
Personal data
GDPR
Data Protection Officer, record of processing activities, DPIA.
We build our security and compliance standards systematically, to give our customers' data the highest level of protection.
The international standard for information security management
ISMS in place, aligned with the latest version of the standard
Compliance with the General Data Protection Regulation
Full compliance with GDPR requirements
Core Rule Set for advanced web application protection
Standard OWASP rules implemented against web attacks
An audit of system security and organisational controls
Certification process planned with an independent auditor
Six mechanisms a large organisation's security team asks about. Under each description, the technical names for the people in IT.
People sign in with their company account, so you manage access on your side rather than in a separate password store.
Every account has only the permissions it needs for its work - not one more.
We encrypt data where it is stored, and in transit between the browser and the platform.
The platform runs on Microsoft Azure, in data centres within the European Economic Area. You can verify the infrastructure provider independently of us.
Systems are under constant watch, so we see an outage or unusual traffic straight away, not from a report.
Backups are created automatically, with no human involved and nothing to remember.
Regular security testing is carried out by a certified external partner. Below is the result of the most recent test - with the date and the number of findings in each severity band, because without those a test result means nothing.
The main Gamfi application, 3 February 2025
Vulnerabilities found:
All vulnerabilities have been fixed
The test is run by an external, certified partner, not by our own team. We repeat the tests regularly and fix the vulnerabilities we find.
Everything we can bring to a security review. We share policies, procedures and legal documentation on request.
Systems in place
Information security
Personal data protection
The questions we get by email during a security review.
We work within an information security management system aligned with ISO/IEC 27001:2022. We have policies and procedures covering system access, incidents, data retention and business continuity. We run internal and external audits on a regular basis.
We process data in line with the GDPR. We encrypt it where it is stored (AES-256) and in transit between the browser and the platform (TLS 1.2/1.3). Processing takes place within the European Economic Area. We have appointed a Data Protection Officer, and for projects and systems that process personal data we carry out a data protection impact assessment (DPIA, GDPR art. 35).
Yes. The policies cover access management, incidents, passwords and authentication, data retention and information classification. All of it sits within an information security management system aligned with ISO/IEC 27001, and we check regulatory compliance on an ongoing basis.
We follow a defined procedure: we identify, log and analyse the incident, and where required we report it to the competent authorities in line with GDPR art. 33. There are named people on the team responsible for security.
The platform runs on Microsoft Azure, in data centres within the European Economic Area. Azure holds certifications including ISO 27001 and ISO 27701, and SOC 1, SOC 2 and SOC 3 reports.
We maintain a business continuity plan (BCP). The platform runs on a high-availability architecture with redundancy, and backups are created automatically every 24 hours.
Write to us. We share policies, procedures and legal documentation on request.
Questions about architecture, data processing and compliance are answered by the person responsible for them, not by the sales team. Tell us what you need for your security review.