Security
Payloads
Whatever you enqueue. Encrypted at rest with AES-256, keys rotated every 90 days.
Metadata
Queue names, timings, attempt counts, error strings. Kept for your retention window.
Account
Email, name, and the audit log of who did what in the dashboard.
Not held
No payment card data. Billing runs through Stripe and we store the last four digits only.
7, 30 or 90 days
By plan. History older than the window is deleted nightly.
Dead letter
Kept for the same window, then exported to you or deleted, your choice.
Backups
Encrypted, 35 day rolling. A deletion is gone from backups inside 35 days.
Deletion request
Whole project wiped inside 7 days, with a written confirmation.
Least privilege
Four people can reach production. Every access is logged and reviewed monthly.
No payload reading
Support cannot read payloads. They see counts, states and error classes.
Customer keys
On Scale you hold the key and we hold ciphertext we cannot open.
SSO and SCIM
SAML and SCIM on Scale, with enforced 2FA on every plan.
No ISO 27001, no HIPAA BAA, and no FedRAMP. SOC 2 Type II is from May 2026 and is available under NDA. If one of those is a hard requirement, say so on the first call and we will tell you whether it is on the roadmap or not.
Page last reviewed 1 September 2026. Report a vulnerability: security@gantry.dev, PGP on request, 72 hour first response.