Security & Compliance
How Greg keeps your operator data safe.
The controls, encryption, and processes behind every Greg deployment. Need our full security packet? Request it below.
Data handling
Greg processes calls, transcripts, leads, and CRM events on operator-isolated infrastructure. Customer data is never used to train shared models. Retention windows are configurable per workspace.
Access controls
Role-based access with least-privilege defaults. SSO available on enterprise plans. All privileged actions are logged and reviewable.
Encryption
TLS 1.3 in transit. AES-256 at rest. Keys managed by a dedicated KMS with rotation policies and per-tenant envelope encryption for sensitive payloads.
Subprocessors
An up-to-date subprocessor list is maintained and provided on request. Material changes are communicated to customers in advance.
Incident response
24/7 on-call rotation. Defined severity tiers with notification SLAs. Post-incident review reports shared with affected customers.
HIPAA / BAA
Greg is HIPAA-ready. A signed Business Associate Agreement is required before PHI is processed and is available on request.
Pen-testing
Independent third-party penetration tests on an annual cadence. Summary report available under NDA.
Vulnerability disclosure
Responsible disclosure welcomed at security@glaciersystemsmanagement.com. Findings are triaged within one business day.