Security & trust

Built to be checked

Procurement teams, data protection officers and IT reviewers all ask the same question in different words: can we trust this supplier with our workforce data? This page is the straight answer, with the evidence you need for a security questionnaire or a tender.

Request security documentation

ISO/IEC 27001:2022

Gyzer Technologies Ltd

Certificate number
260792
Certification body
British Assessment Bureau
Accreditation
UKAS Management Systems
Initial certification
7 February 2025
Valid to
6 February 2028

Subject to annual assessment. Scope covers software development and IT consultancy, cyber security, digital transformation and software management solutions including mobile and web application development.

Information security

A certified management system, not a list of good intentions

Glix is provided by Gyzer Technologies Ltd, registered in England and Wales, company number 15058377. The information security management system is certified to ISO/IEC 27001:2022 by a UKAS-accredited certification body.

Access control

Role-based permissions with least-privilege access, authentication controls, and location-scoped managers who see only their own contracts. Bespoke roles and per-organisation permissions on Enterprise agreements.

Encryption and monitoring

Encryption in transit and at rest where appropriate, with logging and security monitoring across the platform.

Secure development

Secure software development practices, environment separation, controlled release processes, and vulnerability and patch management.

Resilience

Backup and recovery arrangements and business continuity planning, tested rather than assumed.

Incident management

Documented incident response procedures. Where Glix acts as processor, qualifying personal data breaches are reported to the customer organisation in line with the Data Processing Addendum and applicable law.

Supplier assurance

Subprocessors are assessed before use and bound by contractual confidentiality, security and data protection obligations. A current list is available on request.

We publish what a buyer needs to assess risk. We do not publish detailed implementation specifics that would help someone attack the platform.

Data protection

UK data residency and a GDPR toolset in the product

Where data lives

Primary production customer data is hosted in the United Kingdom. Where an approved subprocessor processes limited data outside the UK, recognised transfer safeguards apply, including the UK International Data Transfer Agreement or the UK Addendum to standard contractual clauses.

Controller and processor

Your organisation is the controller for workforce data. Gyzer acts as processor under your documented instructions and the Data Processing Addendum, which forms part of the agreement and is available on request.

Subject access requests

A subject access request export is built into the product, so you can answer a worker or a DPO without raising a support ticket.

Retention you control

Evidence retention is configured per organisation with per-location override. Notes carry retention categories. You set retention to match your own legal obligations.

Honest expiry

When photo evidence reaches the end of its retention period the file is deleted and the record keeps a removed-state marker and the date, so storage limitation does not put a hole in your audit trail.

Payments

Checkout, plan changes and invoices run through Stripe. Glix never holds your card details.

Safety architecture

Why lone worker protection survives a failed payment

Ungated by design

SOS, duress, check-ins, escalation, SMS alerts and last-known location ship on every tier. Safety is not an upgrade you can forget to buy.

The failed-payment test

Entitlements are driven live by billing state. When a payment fails, the account moves to a read-only grace lock that preserves safety, so a billing problem never becomes a safety problem.

What Glix is not

Glix is not an emergency service, an alarm receiving centre or a response provider. It escalates to responders you nominate, and it depends on networks, devices and people. In an emergency, always call 999.

Procurement

What we can send your procurement team

Compliance and IT leads working through a supplier security review together

Available on request

  • ISO/IEC 27001:2022 certificate of registration
  • Data Processing Addendum
  • Current subprocessor list
  • Completed security questionnaires
  • Information on transfer safeguards
  • Custom data retention terms on Enterprise agreements

Request procurement pack

Who to contact

Security and vulnerability reports
support@glixapp.com with the subject “Security vulnerability”. Please report privately and give us a reasonable opportunity to investigate before any public disclosure.
Privacy and data protection
support@glixapp.com. Full detail is in the privacy policy.
Procurement and contracts
support@glixapp.com, or see the terms of service.
Accessibility
See the accessibility statement.
Registered office
Gyzer Technologies Ltd, 20-22 Wenlock Road, London, N1 7GU, United Kingdom. Registered in England and Wales, company number 15058377.
ICO registration
Gyzer Technologies Ltd is registered with the Information Commissioner’s Office under reference ZB712909, verifiable on the ICO data protection register.

This site sets analytics cookies only with your consent, and never for advertising. See the cookie policy for every cookie and storage key we use.

Operations manager and team leader reviewing Glix together before starting a trial

Trust is easier to verify than to promise

Book 20 minutes with us and bring your security questionnaire. We would rather answer it live than send a PDF.

14-day trial, no card, full Pro features

Before you go, try Glix on your own sites

See how Glix helps organisations manage mobile workers, shifts, lone-worker safety, patrols, attendance and compliance from one platform. 14-day trial, no card, no sales call.