How Greg keeps your operator data safe.

    The controls, encryption, and processes behind every Greg deployment. Need our full security packet? Request it below.

    Data handling

    Greg processes calls, transcripts, leads, and CRM events on operator-isolated infrastructure. Customer data is never used to train shared models. Retention windows are configurable per workspace.

    Access controls

    Role-based access with least-privilege defaults. SSO available on enterprise plans. All privileged actions are logged and reviewable.

    Encryption

    TLS 1.3 in transit. AES-256 at rest. Keys managed by a dedicated KMS with rotation policies and per-tenant envelope encryption for sensitive payloads.

    Subprocessors

    An up-to-date subprocessor list is maintained and provided on request. Material changes are communicated to customers in advance.

    Incident response

    24/7 on-call rotation. Defined severity tiers with notification SLAs. Post-incident review reports shared with affected customers.

    HIPAA / BAA

    Greg is HIPAA-ready. A signed Business Associate Agreement is required before PHI is processed and is available on request.

    Pen-testing

    Independent third-party penetration tests on an annual cadence. Summary report available under NDA.

    Vulnerability disclosure

    Responsible disclosure welcomed at security@glaciersystemsmanagement.com. Findings are triaged within one business day.