Trust Center

    Everything you need to evaluate gtwy's security.

    Certified controls, a public subprocessor list, and the legal paperwork your team needs, without waiting on an email thread.

    SOC 2 Type II — CertifiedISO 27001 — CertifiedSecurity response time — 24 hours

    Certifications & frameworks

    AICPA SOC accredited logo
    Certified

    SOC 2 (Type II)

    Independent audit of security, availability, and confidentiality controls across the platform.

    Full report — available on request

    ISO 27001 certification
    Certified

    ISO 27001

    Information security management system covering infrastructure, access control, and incident response.

    Certificate — available on request

    Compliant

    GDPR & CCPA

    Data processing terms, subprocessor disclosure, and deletion workflows are set out in the Data Processing Addendum.

    DPA — available on request

    Subprocessors

    22 vendors
    VendorCategoryPurposeRegion
    OpenAIAI providerChat completion, embeddings, image generationGlobal
    AnthropicAI providerChat completion & batch inferenceGlobal
    Google GeminiAI providerChat completion & multimodal inferenceGlobal
    GroqAI providerLow-latency inference routingGlobal
    Grok (xAI)AI providerChat completionGlobal
    Mistral AIAI providerChat completionGlobal
    DeepgramAI providerSpeech-to-text transcriptionGlobal
    OpenRouterAI aggregatorRoutes to additional third-party modelsGlobal
    NeevCloudAI providerGPU inference hostingGlobal
    Moonshot AIAI providerChat completionGlobal
    DeepSeekAI providerChat completion, reasoningGlobal
    MiniMaxAI providerChat completion, reasoningGlobal
    NotDiamondRoutingAutomatic model routing across providersGlobal
    Google Cloud PlatformInfrastructurePrimary hosting & computeSelf-hosted (GCP)
    CloudflareInfrastructureCDN / network layerGlobal (edge network)
    MongoDBData storePrimary application databaseSelf-hosted (GCP)
    PostgreSQL / TimescaleDBData storeMetrics & time-series storageSelf-hosted (GCP)
    RedisData storeCaching & session stateSelf-hosted (GCP)
    RabbitMQInfrastructureAsync job & message queueingSelf-hosted (GCP)
    PostHogAnalyticsProduct usage analyticsGlobal
    RTLayerReal-timeLive event & notification deliveryGlobal
    Cal.comSchedulingDemo & sales meeting bookingGlobal
    Last reviewed 2026-09-02Adding or removing a vendor triggers a 30-day notice to customers under the DPA.

    FAQ

    Do you sign custom DPAs?+

    Our standard DPA covers most cases, and can include Standard Contractual Clauses for international transfers where applicable. Redlines go through legal review on request.

    Where is customer data hosted?+

    gtwy's infrastructure is self-hosted on Google Cloud Platform in a single region, located in India. See the subprocessor list above for every third party in the data path.

    How do I get the full SOC 2 report?+

    The certification summary is public on this page. The full audit report is shared under NDA — email [email protected] and our security team will respond within 24 hours.

    What happens to our data if we leave?+

    Data export and deletion timelines on account closure are set out in the Terms of Service.

    Need the full report?

    SOC 2 report and signed DPA, sent to your work email.

    Email [email protected]