Back to home

Trust and Security

Last updated: September 2026

Glossi holds your 3D models, renders, and product data. This page describes how that data is stored, protected, and accessed, and how we operate the platform. Questions go to contact@glossi.io.

Infrastructure and data location

Glossi runs on managed cloud providers and operates no self-managed network infrastructure. Customer data is stored in the AWS us-east-2 (Ohio) region.

Encryption

Access and authentication

Application security

Monitoring and incident response

Datadog collects application metrics, traces, and logs, and alerts engineering when thresholds are breached. Sentry reports application errors. Infrastructure signals come from AWS CloudWatch. Engineering coverage spans Berlin and the US West Coast.

Incidents are triaged by severity. Customers affected by an incident are contacted directly, by email and through in-product messaging.

Vulnerability management

Vulnerabilities are found through Dependabot, secret scanning on every pull request, a production dependency audit in CI, and the managed scanning our cloud providers run on their infrastructure. Findings are prioritized and tracked to remediation.

Your data

Sub-processors

The services that participate in operating the platform: Amazon Web Services (storage, rendering, queues, CDN), Vercel (web hosting), Render (API hosting), MongoDB Atlas (database), Auth0 (authentication), Stripe (payments), Doppler (secrets), Datadog and Sentry (monitoring), and Intercom (customer messaging). Each is covered by the provider's own security program and service terms.

Reporting a security issue

If you believe you have found a vulnerability in Glossi, email contact@glossi.io with the details. We will acknowledge the report and keep you informed while we investigate.