Skip to content
Sign In Try Free
Workflow-specific products Content, decks, briefs, proposals, legal, and sales each have a clearer buying path.
Review before delivery Draft, edit, collaborate, approve, and export in the same workspace.
Security + procurement path Security policy, support, and Azure Marketplace buying are public.

Trust Centre

Last updated: September 21, 2026

This page is written for the person doing your security review. It is meant to be read end to end in about ten minutes and to answer most of a standard questionnaire without anyone sending an e-mail. The section you should read first is what Gixo does not have — if something there disqualifies us, everything above it was a waste of your afternoon.

Who you are buying from

Gixo is a product of Zencraft Consultancy Private Ltd., registered in Mumbai, Maharashtra, India. It is founder-operated: one person builds it, operates it, answers security@gixo.ai and holds every administrative role. That single fact is the reason behind several of the answers further down this page, so it is stated at the top rather than discovered at the bottom.

Every Gixo product is served by the same application from the same database, so everything on this page applies to all of them.

Where your data is held

The application and its database run on Microsoft Azure in the United States. The table below lists every region Gixo's own configuration names and what runs in each; every region in it that handles customer data is in the US. Beyond that table, data can be processed outside the United States in three ways. At least one Azure OpenAI model deployment is Global Standard, a deployment type Azure may run in any of its regions, so a prompt sent to it can be processed outside the US; the repository records the deployment type of only one model deployment, so others may be Global Standard as well. Requests reach the application through Azure Front Door, whose edge locations around the world terminate TLS. And third-party providers process what Gixo sends them in their own locations, which this table does not cover. There is no residency choice.

What runs there Region What of yours reaches it
The application and its database (Azure Cosmos DB for MongoDB) United States (the configuration does not name which region) Everything a customer stores in the product.
The Log Analytics workspace the application's telemetry is queried in Central US Diagnostic and usage telemetry.
The storage account each deploy uploads the application package to Central US Application packages. The configuration does not say what else the account holds.
The AI model gateway (LiteLLM), a container app East US Every AI prompt and response sent through the gateway, in transit.
The PDF conversion service (Gotenberg), a container app East US Presentations while they are converted to PDF.
Azure OpenAI model deployments and Azure Speech East US 2 AI prompts, text to be read aloud and audio to be transcribed.
Google Vertex AI, for the one model the gateway routes there us-central1 (Iowa, United States) AI prompts for that model.
A staging storage account the deploy passes the application package through West India Application packages. Nothing in the application reads or writes it.
A Front Door route, /proxy/*, to a separate container app Central India Nothing the application sends: no part of it calls that route.
The origin in an older Front Door template, for a profile the deploy does not use West US 2 Nothing through the current deploy, which purges a different Front Door profile.
Who else sees your data

Gixo publishes a sub-processor register of the processors it has engaged for the product, kept by hand. It is not a complete list of every third party that receives personal data. The public website also loads analytics, session-recording and marketing-attribution tools, which receive visitor data: IP address, device and browser details, page and click behaviour, session recordings, and for Microsoft Clarity and PostHog a pseudonymous account identifier when the visitor is signed in. The ones that load today are Google Analytics and Google Ads, Microsoft Clarity, PostHog, Ahrefs Analytics and ipapi.co. The affiliate trackers, Reditus, Affonso and Lemon Squeezy's, are built in but switched off while the partner programme is paused. None of the analytics tools is on the sub-processor register; they are recorded in Gixo's Article 30 record of processing activities.

The register itself is on the sub-processor page, with the data each processor receives. Read it as the processors Gixo has engaged, not as every recipient, and read its location column with the region table above.

What the code does

Each statement in this section is checked before every deploy by a test that reads the code or configuration it describes, as is each row of the region table above and each "what exists instead" below. Two facts on this page are the founder's own and no test can read them: that Gixo is founder-operated, and that the application and its database are in the United States. A statement that could not be checked either way was taken off.

A session can be cut off now. Disabling or closing an account refuses its existing sign-in cookies on their next request, rather than letting them run until they expire. The check sits inside the cookie handler, before any authorisation filter.

Some privileged actions are recorded. These write to one audit store: seat grants and releases and policy changes in an organisation, team membership changes, guest-share approvals, session revocations, account closure, and for content, creating, editing and deleting it through the core content service, restoring it from the trash, removing it for good, and editing a Lex clause. That is not every way content can be created or changed: an import or an upload, for example, writes no audit row. Your own administrators can read your team's rows from inside the product. Organisation seat and policy changes are keyed on the organisation rather than a team, so they are not on that screen yet; ask and we will produce them.

Audit records expire on a schedule. Audit records are kept 365 days and then deleted automatically by a database expiry stamped on each row as it is written.

AI calls are traced, and the traces expire. An AI call the platform traces records the provider, the model that was asked for and the model that actually answered. Traces are kept 90 days and then deleted by the same kind of database expiry.

Deleting from the content library is not immediate. An item deleted from the content library goes to a trash for 30 days, images included, and can be restored within that window. After it, the item is removed for good, with its images and the source text stored in its own folders. There is no trash screen in the product yet, so a restore is done on request: e-mail security@gixo.ai. Two things remove work without the trash window: closing an account, and the Lex retention purge after an account's Lex access has ended.

Your account record downloads at any time. Your account record downloads from your profile settings whenever you want it. An archive of the work itself is not self-service yet. It is available on request: e-mail security@gixo.ai and we will produce it.

URLs you supply cannot reach our internal network. URL imports and image fetches validate the address and then connect to the address they validated, rather than resolving the name a second time.

Dependencies are checked in CI. Dependabot watches the NuGet and npm dependencies, gitleaks scans for committed secrets, and a known-vulnerable-dependency check and a software bill of materials run in GitHub CI. The dependency check fails the CI run on any high- or critical-severity advisory that has not been accepted on its allow-list. None of this gates a release: deploys run from the founder's machine and do not wait for CI.

Card details never reach Gixo. Card numbers and security codes are entered on the payment provider's own checkout, and nothing in Gixo's code has a field that holds either. Gixo stores the resulting transaction record.

Processing is documented. A GDPR Article 30 record of processing activities exists, and it cites the source files it was read from. Ask and we will send it.

What Gixo does not have

If your review requires any of the following, Gixo does not have it today. Each one says what is absent, what exists instead, and why it is absent. We would rather you knew before signing than after.

SOC 2 Type I or Type II report

No. Gixo has no SOC 2 report of any type, and no audit has been commissioned.

What exists instead: What we hand a reviewer instead is this trust centre, the published security policy, the sub-processor register and, on request, the Article 30 record of processing activities. The cloud provider's own certifications cover the provider's infrastructure and say nothing about Gixo's controls, so they are not offered as a substitute.

Why: A SOC 2 costs USD 20,000-60,000, needs a three- to twelve-month observation window before a report exists at all, and several of its controls presuppose more than one employee.

ISO/IEC 27001 certification

No. Gixo holds no ISO 27001 certificate.

What exists instead: What is ours is published rather than certified: the security policy, this trust centre, and the gaps listed on it.

Why: USD 15,000-40,000 plus annual surveillance audits, and the standard requires separation between the person who performs a control and the person who reviews it. Gixo is one person.

ISO/IEC 42001 AI management system

No. Gixo holds no ISO 42001 certificate and makes no claim of alignment to it.

What exists instead: Nothing that has been assessed against the standard. What exists is a record: an AI call the platform traces stores the provider, the model that was asked for and the model that actually answered.

Why: The same blockers as ISO 27001. A partial "aligned to ISO 42001" claim would be worse than this answer, because nobody has assessed it against the standard.

Recent third-party penetration test

No. There is no third-party penetration test report, recent or otherwise.

What exists instead: What runs instead is automated: Dependabot, committed-secret scanning, a known-vulnerable-dependency check that fails a CI run, and a generated SBOM, all in GitHub CI. None of them gates a release, because deploys do not wait for CI. Fetches of user-supplied URLs connect to the address that was validated rather than re-resolving the name.

Why: This one is not blocked by headcount. At USD 4,000-15,000 it is the cheapest real procurement artifact available and it simply has not been bought yet. It is the answer here most likely to change.

SAML 2.0 / enterprise SSO federation

No. Gixo supports no SAML federation and cannot federate with your identity provider.

What exists instead: Sign-in is OIDC-brokered through Descope, including Google, Microsoft, LinkedIn and Facebook. A disabled or closed account's existing sessions are refused on their next request rather than surviving until the cookie expires.

Why: Federation needs an enterprise tier from our identity provider, which is priced per named prospect rather than bought speculatively.

SCIM 2.0 user provisioning

No. There is no SCIM endpoint and no automated directory provisioning.

What exists instead: Seats are invited and released from the organisation console by your own administrators, and every grant and release is written to the audit store as it happens. That particular record is keyed on the organisation, and the customer-facing audit screen reads team-scoped records, so it is not on that screen today — ask and we will produce it.

Why: SCIM sits on top of federation we do not have, and its value is automatic de-provisioning at hundreds of seats. Below that, invite-and-release is the correct answer rather than a cheaper one.

Separation of duties / four-eyes on privileged actions

No. One person holds every administrative role, so no action requires a second approver.

What exists instead: The actions listed under the audit trail above are recorded instead of being gated: they write to one audit store with a 365-day retention, and a customer's own administrators can read their team's rows without asking us.

Why: Separation of duties means two people. It is not a code change, and we will not describe a control we cannot staff.

EU data residency

No. There is no EU residency option, and no data-residency choice of any kind.

What exists instead: The application and its database run in the United States, and every region Gixo's configuration names is listed on this page with what runs there. A Data Processing Agreement is published, and the Article 30 record of processing activities is available on request.

Why: An EU option means a second copy of the application and database outside the US, and roughly double the infrastructure bill for a business this size.

Per-tenant database or physical isolation

No. All customers share one database and one application.

What exists instead: Separation is logical and enforced server-side rather than by deployment: a team's audit trail read takes the team as a required argument, ANDs it itself, and discards any team the caller supplied.

Why: Physical isolation would be a live migration per tenant, and there is no staging environment to rehearse one in.

Multi-region failover / disaster recovery with stated RPO and RTO

No. Gixo has no standby deployment and no failover between regions, and publishes no RPO and no RTO.

What exists instead: Azure's own platform availability, with Azure Front Door in front of the application. We have not performed a restore drill, so we will not quote a recovery objective we have never measured.

Why: A second region needs double the bill, a messaging backplane and an on-call rota. The restore drill is the cheap half and it is on the list.

Customer-managed encryption keys (CMK / BYOK)

No. You cannot supply or hold your own encryption keys.

What exists instead: Encryption of stored data at rest is the Azure services' own default. Gixo's deployment configures no encryption setting of its own and holds no key a customer could control, so the default is Microsoft's to describe, and we will point you to Microsoft's documentation of it.

Why: CMK needs a new database account and a full data migration.

HIPAA Business Associate Agreement

No. Gixo will not sign a BAA. Do not put protected health information into it.

What exists instead: For personal data generally, a GDPR Article 28 Data Processing Agreement and an acceptable-use policy are published.

Why: A BAA commits to the HIPAA Security Rule, which presupposes a security organisation Gixo does not have.

Contractual uptime SLA with service credits

No. There is no uptime commitment and no service credits in any Gixo contract.

What exists instead: A health endpoint that every deploy checks before it is declared finished. What we will not do is put a number next to it: we do not publish measured availability, so there is no figure behind a percentage we could write down.

Why: An SLA needs a quarter of measured availability, a tested restore, and a decision to accept financial liability for a service with no standby deployment.

SIEM and 24/7 security monitoring

No. There is no SIEM, no security operations centre and no 24/7 security on-call.

What exists instead: The audit trail described above, and a published disclosure address, security@gixo.ai, that the founder reads.

Why: Gixo is founder-operated. Plan for a bus factor of one — that is the honest planning assumption, and it is the reason several other answers here are also no.

Questions this page cannot answer yet

Each of these could have been written as a confident sentence that would probably be right. A trust centre whose first claim turns out to be wrong is worse than one with a gap in it, because you then have no way to tell which of the other statements were also only probably right. So these are published open.

Does the affiliate programme still pay out through Lemon Squeezy?

What is known: Polar is the merchant of record for customer purchases, and Lemon Squeezy is on the sub-processor register as historical with one legacy shop-checkout path still configured as a fallback. Affiliate payouts are a separate commercial arrangement from merchant-of-record, and nothing in this repository settles which provider currently makes them. The partner programme is paused, so no affiliate tracker loads on the website today.

Who can settle it: The founder, from the affiliate platform's own console. It changes who appears on the register as a current processor of affiliate payment data, so nothing has been published either way.

Other documents

These are published separately and are not held to the check described above. Where one of them disagrees with this page, this page is the one checked against the code.

Security policy — incident response and vulnerability disclosure.

Sub-processor register — the processors Gixo has engaged, with the data each receives.

Security and procurement

security@gixo.ai
Questionnaires, vulnerability reports and anything on this page reach the same person.

Registered address

Zencraft Consultancy Private Ltd.
A/10, Nootan Nagar, First Floor,
Bandra West,
Mumbai 400050
Maharashtra, India