AccountGauge
ProductPricingSecurityDocsAboutContact
Sign inBook a demo
AccountGauge

Gauge relationship strength before revenue is at risk. Purpose-built for professional services firms.

getaccountgauge.com

Product

  • Overview
  • Pricing
  • Security
  • Documentation

Company

  • About
  • Contact
  • Careers
  • Blog

Legal

  • Privacy Policy
  • Terms of Service
  • Cookie Policy
  • DPA

Connect

  • hello@getaccountgauge.com
  • LinkedIn
  • X (Twitter)

© 2026 AccountGauge, Inc. All rights reserved.

PrivacyTermsCookies
Trust Center

Security is foundational, not an afterthought

Your client relationships are sensitive data. AccountGauge is architected from the ground up with encryption, isolation, and auditability so you can meet your compliance obligations with confidence.

Security quick facts

  • TLS 1.3 in transit
  • AES-256 at rest
  • Logical tenant isolation
  • RBAC with least privilege
  • Immutable audit logs
  • Automated daily backups
  • SOC 2 Type II ready
  • Real-time monitoring

Have a specific security question? security@getaccountgauge.com

Data protection

Every byte of client data is protected with industry-standard encryption both in motion and at rest.

Encryption in transit

All connections are secured with TLS 1.3. API endpoints enforce HTTPS with HSTS headers and certificate pinning for mobile integrations.

Encryption at rest

Data stored in the database is encrypted with AES-256. Encryption keys are managed through a dedicated KMS with automatic key rotation on a 90-day cycle.

Backup encryption

Automated backups are encrypted using the same AES-256 standard and stored in geographically separated locations to ensure durability.

Tenant isolation & access controls

Strict logical separation and fine-grained access controls ensure each firm's data is visible only to authorized users.

Logical tenant isolation

Every firm operates within its own isolated data boundary. Database queries are scoped to the authenticated tenant at the infrastructure layer, not just the application layer.

Role-based access control (RBAC)

Users are assigned roles (Owner, Manager, Account Manager) with distinct permission sets. Permissions govern access to accounts, reports, settings, and team management.

Immutable audit logs

Every user action (logins, pulse submissions, score views, setting changes) is logged with a timestamp, user ID, IP address, and action type. Logs are append-only and cannot be modified or deleted.

Operational security

Our operational practices are designed around the principle of least privilege and defense in depth.

Least-privilege access

Internal team members access production infrastructure only through short-lived credentials with narrowly scoped permissions. There is no persistent access to customer data.

Automated backups

The database is backed up daily with point-in-time recovery enabled. Backup retention follows a 30-day rolling window with offsite replication.

Monitoring & alerting

Infrastructure and application metrics are continuously monitored. Anomaly detection triggers real-time alerts for unusual access patterns, error spikes, or latency changes.

Compliance posture

AccountGauge is engineered to meet the requirements of common compliance frameworks. We operate with the rigor expected of a SOC 2-compliant organization.

SOC 2 Type II readiness

Our controls, policies, and infrastructure are aligned with the AICPA Trust Services Criteria across security, availability, and confidentiality. We are actively working toward formal SOC 2 Type II certification.

Data residency awareness

Managed deployments run in the United States by default. Self-hosted customers can choose their own data residency region to comply with local regulations.

Data processing & retention

We process only the data necessary to deliver the service. Data retention policies are configurable per-tenant, and data deletion requests are honored within 30 days.

Incident response & vulnerability disclosure

We maintain documented incident response procedures and welcome responsible disclosure from the security community.

Incident response plan

Our incident response plan covers identification, containment, eradication, recovery, and post-incident review. Affected customers are notified within 72 hours of a confirmed data breach, or sooner where required by law.

Vulnerability disclosure

If you discover a potential security issue, please report it to security@getaccountgauge.com. We commit to acknowledging reports within 2 business days and providing resolution timelines within 5.

Self-hosting security guidance

For firms that deploy AccountGauge on their own infrastructure, we provide clear guidance to maintain the same security posture.

Environment variables & secrets

All sensitive configuration (database credentials, API keys, encryption keys) must be stored as environment variables or in a secrets manager. Never commit secrets to version control.

Database hardening

Use a managed database service with encryption at rest enabled. Restrict network access to the database to only your application servers. Enable connection encryption (SSL/TLS).

Backups & disaster recovery

Configure automated daily backups with at least 14 days of retention. Test restores quarterly. Store backups in a separate region from your primary deployment.

Security quick facts

  • TLS 1.3 in transit
  • AES-256 at rest
  • Logical tenant isolation
  • RBAC with least privilege
  • Immutable audit logs
  • Automated daily backups
  • SOC 2 Type II ready
  • Real-time monitoring

Have a specific security question? security@getaccountgauge.com

On this page

Data protectionTenant isolation & access controlsOperational securityCompliance postureIncident response & vulnerability disclosureSelf-hosting security guidance

Need more detail?

We are happy to walk through our security architecture, share our policies, or answer specific questions from your compliance team.

Contact our teamsecurity@getaccountgauge.com

We respond to security inquiries within 2 business days.