Security and privacy

Built so that a stolen password is not enough.

Guzloo has no passwords to steal: people sign in with their phone. Everything sensitive asks for a fresh code, and personal data is encrypted with keys that are rotated.

Phone sign-in with one-time codes

People sign in with their phone number and a one-time code sent by SMS, or with an authenticator app or a passkey. Repeated wrong codes freeze the number for a while.

A fresh code for anything sensitive

Changing a phone number, transferring ownership, changing a bank or salary account, regenerating API keys and downloading an organisation's data each ask for a new code.

Encryption with keys of its own

Personal fields such as phone numbers, addresses, bill-to details and form answers are encrypted with AES-256-GCM keys from Guzloo's own key service. Keys expire and data moves to new keys as it is read.

Roles for every product

Owners and admins decide what each role may do in each product. Guests see only what they are invited to, and their access can end on a date.

Audit log

Sign-ins, membership changes, approvals, billing changes and admin actions are recorded with who did them and when.

Data in India

Guzloo runs on Amazon Web Services in the Mumbai region (ap-south-1). Test, staging and production run in separate AWS accounts.

How we handle personal data, and your rights, are set out in our Privacy Policy. To report a security concern, write to [SUPPORT EMAIL].