GateBud

Security Overview · Last updated 12 September 2026

This page is an overview for prospective and existing customers. GateBud's contractual security commitments are in the Privacy & Security Schedule to the Master SaaS Agreement.

1. Security approach

GateBud™ limits access to customer data, encrypts it in transit and keeps each organisation's data separate.

  • Access to customer data is restricted to people who need it.
  • GateBud uses established managed cloud providers for hosting and database infrastructure.
  • Security controls are reviewed as the product and its infrastructure change.

2. Infrastructure

GateBud runs on established managed cloud providers rather than its own physical servers or data centres.

At a high level:

  • Cloud-hosted architecture. The application and database run on reputable managed cloud services.
  • Managed infrastructure. Operating systems, database engines and platform patching are managed by our providers, which means critical infrastructure security updates are applied promptly and consistently.
  • Redundancy and availability. Our providers offer redundant, highly available infrastructure. Our application is designed to take advantage of that.
  • Continuous monitoring. We use monitoring and error-tracking tools to observe the health of the platform and to alert us to problems.
  • Data location. Customer data is hosted in Australia (Sydney), and may be processed in New Zealand and other jurisdictions used by our reputable cloud providers. See section 9 and the Privacy & Security Schedule.

Specific provider names are available on request and, where relevant, listed in our subprocessor information. Providers may change over time (see section 10).

3. Account security

Access to GateBud is controlled through individual user accounts.

  • Authentication. Users sign in through our authentication system, which is built on a reputable managed authentication provider.
  • Multi-factor authentication (MFA). MFA is not currently available for customer sign-ins. GateBud's administrative access to production infrastructure is protected by MFA (see section 6).
  • Password security. Passwords are stored using industry-standard one-way hashing by our authentication provider; GateBud never stores plain-text passwords.
  • Session management. User sessions are managed securely, with sign-in tokens handled according to current best practice.
  • Role-based permissions. Access within an organisation's account is governed by roles, so users see and do only what their role allows.

4. Data protection

  • Encryption in transit. All connections to GateBud are encrypted using HTTPS/TLS. Data moving between you and the platform is protected in transit.
  • Encryption at rest. Customer data is encrypted at rest where supported by our infrastructure providers.
  • Data segregation. GateBud is a multi-tenant platform. Each organisation's data is logically separated, and access controls are enforced at the database level (row-level security) so one customer cannot access another customer's data. Cross-tenant isolation is verified by automated tests that run before every release.
  • Access controls and least privilege. Access to production systems and customer data is restricted to the people who genuinely need it, on a least-privilege basis.
  • Secure backups. Customer data is backed up daily. Backups are protected by the same access controls, and an independent encrypted copy is held with a separate provider. See section 7.

5. Application security

We build and maintain GateBud with security in mind throughout the development process.

  • Development and review. Changes are reviewed and tested before they reach production. Production is never edited directly.
  • Deployment safety. Changes ship through preview environments before production, and production deployments are atomic, so users are not exposed to half-deployed changes. Releases can be rolled back quickly if a problem is detected.
  • Dependency management. We use well-maintained, reputable libraries and keep dependencies reasonably up to date, applying security updates as needed.
  • Vulnerability remediation. We monitor for issues in our own code and in our dependencies, and prioritise fixing security-relevant problems.
  • Logging and monitoring. We use error-tracking and logging tools to detect, diagnose and respond to problems.

GateBud is not currently ISO 27001 or SOC 2 certified.

6. Operational security

  • Change management. Changes follow a consistent process: develop, review, test on a preview environment, then release to production, with the ability to roll back.
  • Monitoring. We monitor platform health and errors and are alerted to significant issues.
  • Incident response. We have a process for responding to security and availability incidents (see section 8).
  • Access reviews. Access to production systems and administrative tools is limited to those who need it and reviewed periodically.
  • Administrative controls. GateBud's own administrative access to production infrastructure and provider accounts is protected by multi-factor authentication and least-privilege principles.
  • Personnel confidentiality. Everyone who works on GateBud is bound by written confidentiality and intellectual property terms before they start.
  • Device security. We maintain a device security policy requiring disk encryption, screen locks and multi-factor authentication on any device used for GateBud work, and we keep an inventory of the hardware and services that hold data.

7. Backup & recovery

  • Daily backups. Customer data is backed up daily through our managed database infrastructure. In addition, an encrypted copy of the database is stored each day with a separate, independent provider, so a backup exists outside our primary infrastructure.
  • Disaster recovery. Our reliance on managed, redundant cloud infrastructure supports recovery from most infrastructure-level failures.
  • Restoration testing. We run an automated restore drill on a monthly schedule that restores the off-site backup into a throwaway environment and verifies the data, most recently confirmed in July 2026.

We do not currently guarantee a specific recovery time objective (RTO) or recovery point objective (RPO) unless separately agreed in writing.

8. Incident response

If a security or availability incident occurs, we follow a high-level process designed to limit impact and keep customers informed:

  1. Detect. Identify the issue through monitoring, alerts, or a report.
  2. Investigate. Assess what happened, what is affected, and how serious it is.
  3. Contain. Take steps to stop the issue spreading and limit its impact.
  4. Recover. Restore normal, secure operation.
  5. Notify. Where an incident materially affects customer data, notify affected customers without undue delay, and provide information to help them meet their own obligations. Our contractual notification commitments are in the Privacy & Security Schedule.
  6. Learn and improve. Review what happened and make changes to reduce the chance of it recurring.

Notification timing depends on the nature and severity of the incident. We act as quickly as reasonably practicable.

We maintain a documented incident response plan, including ransomware scenarios.

9. Privacy

GateBud handles personal information in accordance with the New Zealand Privacy Act 2020 and the Information Privacy Principles.

  • How we handle information collected through our website and direct dealings is described in our Privacy Policy.
  • How we handle personal information within customer data on our customers' behalf is described in our contractual Privacy & Security Schedule.

In short: customers own their data, we process it to provide and support the Services, and we only generate analytics from it in an aggregated and de-identified form that does not identify any customer or individual.

10. Third-party providers

GateBud uses third-party providers for hosting, storage, authentication, email delivery, monitoring, analytics and similar operational services. We assess providers based on the service they supply.

The specific providers we use may change over time as the platform evolves. Because these providers are part of our ordinary operations, we do not seek customer approval for routine operational changes, though we remain responsible for their performance in connection with the Services and will make our current material providers available on request. This is set out in the Privacy & Security Schedule.

11. Customer responsibilities

Security is a shared responsibility. There are practical steps every customer can take to keep their own account secure:

  • Use strong, unique passwords for GateBud accounts.
  • Protect the email account you use to sign in to GateBud with multi-factor authentication. A compromised inbox is the most common way any account gets taken over.
  • Manage user permissions, giving each person only the access they need.
  • Remove access promptly for people who leave your organisation or change roles.
  • Keep devices secure, including keeping browsers and operating systems up to date.
  • Report suspicious activity to us as soon as you notice it.

12. Responsible disclosure

We welcome reports from security researchers and customers who believe they have found a security vulnerability in GateBud.

  • How to report: email security@gatebud.com with details of the issue and, where possible, steps to reproduce it.
  • What to expect: we aim to acknowledge reports within 3 business days, then investigate and address the issue.

Please act in good faith, avoid accessing or modifying other people's data, and give us reasonable time to respond before disclosing an issue publicly.

Trust Centre · Privacy Policy · Terms of Service