Security at Glowria
Effective 10 July 2026.
Our approach
Security is embedded in how we build Glowria, not bolted on. We follow the principle of least privilege, encrypt data in transit and at rest, and rely on managed infrastructure with certified operators. Our approach is reviewed as the product and the threat landscape evolve.
Technical controls
- Encryption in transit — TLS 1.2+ enforced on every public endpoint.
- Encryption at rest — database and object storage encrypted at rest by managed providers.
- Row-Level Security — every application table is protected by database-level policies; access is scoped to the authenticated user, and admin/moderator access is gated by explicit role checks.
- Least privilege — production access is limited to a small operations group; service credentials are rotated.
- Rate limiting & abuse controls — server-side limits on sensitive operations.
- Audit trail — sensitive user and admin actions are recorded in an append-only audit log.
- Private storage buckets — user photos, videos and passport exports are stored in private buckets with signed-URL access.
- Continuous monitoring — application errors and abnormal patterns are captured and reviewed.
Data protection
How Glowria handles personal data — including biometric-like inputs, retention, international transfers, and your rights — is described in the Privacy Policy and Sub-processors list.
Responsible disclosure
If you believe you have found a security vulnerability affecting Glowria, please report it privately to info@glowria.ai. We commit to:
- acknowledge receipt within 3 business days;
- investigate and keep you informed of progress;
- credit valid reports in our advisories where the reporter wishes to be named;
- not pursue legal action against researchers acting in good faith who follow this policy.
Please do not access, modify, or exfiltrate data belonging to other users, do not run automated scanners that generate significant load, and give us reasonable time to remediate before public disclosure.
Incident response
If a personal-data breach affects you, we will notify the competent supervisory authority within 72 hours where required (Article 33 UK GDPR / EU GDPR) and inform affected users without undue delay where the breach is likely to result in a high risk to their rights and freedoms (Article 34).
Contact
info@glowria.ai · PGP key available on request.