Architecture you can inspect.
TheGonch is early. We document the controls that exist today, the boundaries of the current architecture, and what is not yet in place so firms can evaluate the platform accurately.
Database policies restrict the rows a signed-in user can read or change. Privileged server operations use separate authorization checks.
What is in place today.
Each item below is implemented in the current platform. Where a control is provided by an infrastructure provider rather than by TheGonch directly, the row says so.
A small, inspectable stack.
TheGonch runs on a small number of well-known infrastructure providers. Processing regions for providers other than the database are listed on the sub-processors page where confirmed, and marked where confirmation is still pending.
Full sub-processor list →What is not yet in place.
Firms should evaluate TheGonch knowing this list. No dates are given because none are committed. Status is updated as items change.
Talk to the people who built it.
Compliance, technology and security teams can review the platform directly with the engineers responsible for it. Questions are answered by the people who can change the answer.
Request a technical review