Security and compliance

Data security in the Gamfi platform

The Gamfi platform processes employee data and sales results, so before you roll it out your security team, IT and legal will review us. We have gathered here the practices, documents and answers they usually need to close that review.

Page updated: August 2026

Where the data sits

Microsoft Azure, EEA

Data centres within the European Economic Area.

Encryption

AES-256 and TLS 1.2/1.3

Where the data is stored, and in transit to the browser.

Management system

ISO/IEC 27001:2022

An information security management system aligned with the standard.

Personal data

GDPR

Data Protection Officer, record of processing activities, DPIA.

Our certifications and compliance frameworks

We build our security and compliance standards systematically, to give our customers' data the highest level of protection.

ISO 27001:2022

active

The international standard for information security management

Progress100%

ISMS in place, aligned with the latest version of the standard

GDPR

active

Compliance with the General Data Protection Regulation

Progress100%

Full compliance with GDPR requirements

OWASP CRS 3.2

active

Core Rule Set for advanced web application protection

Progress100%

Standard OWASP rules implemented against web attacks

SOC 2 Type I

planned - Q2 '26

An audit of system security and organisational controls

Progress25%

Certification process planned with an independent auditor

How we protect data in practice

Six mechanisms a large organisation's security team asks about. Under each description, the technical names for the people in IT.

Sign-in with a company account

People sign in with their company account, so you manage access on your side rather than in a separate password store.

  • Single Sign-On (SSO)

Least privilege

Every account has only the permissions it needs for its work - not one more.

  • Least privilege principle (minimum access rights)

Encryption

We encrypt data where it is stored, and in transit between the browser and the platform.

  • AES-256 at rest, TLS 1.2/1.3 in transit

Data stays in the EEA

The platform runs on Microsoft Azure, in data centres within the European Economic Area. You can verify the infrastructure provider independently of us.

  • Azure certifications: ISO 27001, ISO 27701
  • Azure reports: SOC 1, SOC 2, SOC 3

Round-the-clock monitoring

Systems are under constant watch, so we see an outage or unusual traffic straight away, not from a report.

  • 24/7 monitoring

Backups every 24 hours

Backups are created automatically, with no human involved and nothing to remember.

  • Automatic backup, at least once a day

Penetration testing

Regular security testing is carried out by a certified external partner. Below is the result of the most recent test - with the date and the number of findings in each severity band, because without those a test result means nothing.

Web application

low risk

The main Gamfi application, 3 February 2025

Vulnerabilities found:

  • Critical: 0
  • High: 0
  • Medium: 0
  • Low: 5
  • Info: 3

All vulnerabilities have been fixed

The test is run by an external, certified partner, not by our own team. We repeat the tests regularly and fix the vulnerabilities we find.

Business continuity

  • We maintain a business continuity plan (BCP) and a disaster recovery plan (DRP)
  • The platform runs on a high-availability architecture with redundancy, so one component failing does not stop the work
  • Backups are created automatically every 24 hours

Documents and policies

Everything we can bring to a security review. We share policies, procedures and legal documentation on request.

Systems in place

  • Information security management systemAligned with ISO/IEC 27001:2022, with internal and external audits.
  • Personal data protection systemAligned with the GDPR, with a Data Protection Officer and full documentation.
  • Privacy policyPublicly available, no request needed.

Information security

  • Information security policyHow we protect information: confidentiality, integrity and availability.
  • Password and authentication policyStandards for creating passwords and the authentication methods we use.
  • Access management policyGranting, changing and revoking access to systems and data.
  • Security incident management policyIdentifying, responding to and reporting incidents.
  • Business continuity policy (BCP/DRP)Keeping critical services running and restoring them after an outage.
  • Information classification and protection policyHow we classify data and what measures we apply to protect it.
  • Content security policy (CSP)What is allowed to run in the browser, so foreign code is blocked.

Personal data protection

  • Personal data protection policyGDPR compliance rules and how we process data.
  • Data subject rights procedureHandling requests for access, erasure and rectification of data.
  • Record of processing activities (RoPA)A register of every process in which we handle personal data.
  • Data retention and deletion policyRetention periods and how data is securely deleted.
  • Data protection impact assessment procedure (DPIA)Risk analysis of new projects from a personal data standpoint.
  • Personal data breach notification procedureWhat we do and what we report in the event of a breach.

Frequently asked questions

The questions we get by email during a security review.

How do you manage information security in your organisation?

We work within an information security management system aligned with ISO/IEC 27001:2022. We have policies and procedures covering system access, incidents, data retention and business continuity. We run internal and external audits on a regular basis.

How do you protect the personal data of employees and customers?

We process data in line with the GDPR. We encrypt it where it is stored (AES-256) and in transit between the browser and the platform (TLS 1.2/1.3). Processing takes place within the European Economic Area. We have appointed a Data Protection Officer, and for projects and systems that process personal data we carry out a data protection impact assessment (DPIA, GDPR art. 35).

Do you have security policies and procedures in place?

Yes. The policies cover access management, incidents, passwords and authentication, data retention and information classification. All of it sits within an information security management system aligned with ISO/IEC 27001, and we check regulatory compliance on an ongoing basis.

How do you respond to a security incident?

We follow a defined procedure: we identify, log and analyse the incident, and where required we report it to the competent authorities in line with GDPR art. 33. There are named people on the team responsible for security.

Where is the platform infrastructure hosted?

The platform runs on Microsoft Azure, in data centres within the European Economic Area. Azure holds certifications including ISO 27001 and ISO 27701, and SOC 1, SOC 2 and SOC 3 reports.

How do you ensure the platform keeps running?

We maintain a business continuity plan (BCP). The platform runs on a high-availability architecture with redundancy, and backups are created automatically every 24 hours.

How do we get your policies and documentation?

Write to us. We share policies, procedures and legal documentation on request.

Send technical questions straight to us

Questions about architecture, data processing and compliance are answered by the person responsible for them, not by the sales team. Tell us what you need for your security review.