How Gezora protects your data
Gezora protects customer data with encryption in transit and at rest, strict access control, hardened infrastructure, and controls that align with SOC 2, GDPR, and HIPAA requirements.
Last updated August 2026
1. Encryption
Gezora encrypts your data at every stage, in transit and at rest, and keeps every secret out of the codebase.
- Transit encryption uses TLS 1.2 or higher for every connection.
- Data at rest is encrypted with industry standard algorithms.
- Secrets such as API keys and credentials are kept in managed secret stores, never in source code.
2. Access control
Access to your data follows least privilege, so people only reach what their role requires, and every access is logged and reviewed periodically. Administrative functions require multi factor authentication.
3. Infrastructure
Gezora runs on reputable cloud providers with network isolation, hardened configuration, automated patching, and continuous monitoring.
Teams with strict data residency needs can choose private hosting, an isolated environment the customer controls directly.
- Reputable cloud infrastructure with network isolation
- Hardened configuration with automated patching
- Continuous monitoring across the environment
4. Compliance
Gezora controls align with the following standards. Specific certification and attestation detail is available under NDA on request.
- Aligns with the SOC 2 Trust Services Criteria.
- Supports GDPR requirements for customers operating in the European Union and the United Kingdom.
- Supports HIPAA requirements for customers handling protected health information.
5. Data handling
Your data belongs to you. It is never used to train models without your explicit written consent.
- No model training on customer data without explicit written consent
- A data processing addendum is available on request
- Sub processor lists are available on request
6. Incident response
Security updates are applied promptly, and an incident response process is in place. Any breach affecting customer data triggers notification aligned with our contractual and legal obligations.
Every deployment ships with these protections
- Encryption in transit and at rest
- Access follows least privilege with multi factor authentication
- Controls align with SOC 2 Trust Services Criteria and support GDPR and HIPAA
- Private hosting available for strict data residency needs
For a security question, or to report a vulnerability under responsible disclosure, contact sales@gezora.ai.
You can also reach the Gezora team by email at sales@gezora.ai, by phone at +92 308 3406338 or +92 336 8447111, or by mail at 228, Rose Commercial, Park View, Lahore, 53720, Pakistan. Our office hours are Monday to Friday, 9am to 8pm. Saturday, 9am to 6pm. Sunday, 9am to 5pm.
Get started
Stop paying people to do what an agent can
Tell us what you want to automate. We will map the workflow, deploy the right agents, and train your team to run them.
- Every agent is trained on your own workflows, never a generic template
- Most deployments are live within two to four weeks
- SOC 2 compliant, with a complete audit trail on every deployment
