Skip to content

Security

What we hold, for how long, and who else sees it.

What we hold, for how long, and who else sees it.

What we hold, for how long, and who else sees it.

Written for the person who has to fill in your vendor form. Everything on this page is true on the day it is published and dated at the bottom.

Written for the person who has to fill in your vendor form. Everything on this page is true on the day it is published and dated at the bottom.

Data we hold

Data we hold

Data we hold

Payloads

Whatever you enqueue. Encrypted at rest with AES-256, keys rotated every 90 days.

Metadata

Queue names, timings, attempt counts, error strings. Kept for your retention window.

Account

Email, name, and the audit log of who did what in the dashboard.

Not held

No payment card data. Billing runs through Stripe and we store the last four digits only.

Retention

Retention

Retention

7, 30 or 90 days

By plan. History older than the window is deleted nightly.

Dead letter

Kept for the same window, then exported to you or deleted, your choice.

Backups

Encrypted, 35 day rolling. A deletion is gone from backups inside 35 days.

Deletion request

Whole project wiped inside 7 days, with a written confirmation.

Access

Access

Access

Least privilege

Four people can reach production. Every access is logged and reviewed monthly.

No payload reading

Support cannot read payloads. They see counts, states and error classes.

Customer keys

On Scale you hold the key and we hold ciphertext we cannot open.

SSO and SCIM

SAML and SCIM on Scale, with enforced 2FA on every plan.

Four subprocessors, and what each one sees.

Four subprocessors, and what each one sees.

Four subprocessors, and what each one sees.

Amazon Web Services

Ireland, Frankfurt, Virginia

Compute, storage, encrypted payloads

Neon

Neon

Frankfurt

Ireland, Frankfurt, Virginia: Frankfurt

Postgres for metadata

Compute, storage, encrypted payloads: Postgres for metadata

Stripe

Stripe

Ireland, United States

Ireland, Frankfurt, Virginia: Ireland, United States

Billing, last four digits of the card

Compute, storage, encrypted payloads: Billing, last four digits of the card

Postmark

Postmark

United States

Ireland, Frankfurt, Virginia: United States

Transactional email, address and name

Compute, storage, encrypted payloads: Transactional email, address and name

What we do not have yet.

What we do not have yet.

No ISO 27001, no HIPAA BAA, and no FedRAMP. SOC 2 Type II is from May 2026 and is available under NDA. If one of those is a hard requirement, say so on the first call and we will tell you whether it is on the roadmap or not.

Page last reviewed 1 September 2026. Report a vulnerability: security@gantry.dev, PGP on request, 72 hour first response.

Create a free website with Framer, the website builder loved by startups, designers and agencies.