← Back to Glowria

Security at Glowria

Effective 10 July 2026.

Our approach

Security is embedded in how we build Glowria, not bolted on. We follow the principle of least privilege, encrypt data in transit and at rest, and rely on managed infrastructure with certified operators. Our approach is reviewed as the product and the threat landscape evolve.

Technical controls

Data protection

How Glowria handles personal data — including biometric-like inputs, retention, international transfers, and your rights — is described in the Privacy Policy and Sub-processors list.

Responsible disclosure

If you believe you have found a security vulnerability affecting Glowria, please report it privately to info@glowria.ai. We commit to:

Please do not access, modify, or exfiltrate data belonging to other users, do not run automated scanners that generate significant load, and give us reasonable time to remediate before public disclosure.

Incident response

If a personal-data breach affects you, we will notify the competent supervisory authority within 72 hours where required (Article 33 UK GDPR / EU GDPR) and inform affected users without undue delay where the breach is likely to result in a high risk to their rights and freedoms (Article 34).

Contact

info@glowria.ai · PGP key available on request.