GATEWAY
Trust & Security

Trust and security for Gateway services.

A concise route into Gateway’s security approach, shared-responsibility model, and current diligence material. Exact controls depend on the service and deployment boundary.

Diligence path

Assess the service you are actually buying.

Security review starts with scope, then connects the operating boundary to current evidence and explicit customer controls.

01

Scope the service

Identify the Gateway service, deployment model, data classes, integrations, and operating parties in scope.

02

Map the boundary

Record access, administration, keys, hosting, monitoring, incident, recovery, and customer responsibilities.

03

Review current evidence

Confirm the legal entity, service, reporting period, exceptions, and available diligence material.

04

Agree shared controls

Carry provider, Gateway, and customer responsibilities into the applicable service and operating documents.

Authoritative evidence

Current assurance material lives in the Trust Center.

Review the current report, certificate, policy, scope, period, exceptions, and complementary customer controls before relying on an assurance item.

Visit the Trust Center
Operating security

Protection, response, and recovery stay connected.

The applicable practices are selected and evidenced against the contracted service boundary rather than presented as universal claims.

Protect

  • Identity and least privilege
  • Encryption and key boundaries
  • Release and vulnerability handling

Detect and respond

  • Service telemetry and alerting
  • Incident escalation
  • Evidence preservation and communication

Recover and improve

  • Backup and restoration
  • Failure-domain and recovery testing
  • Post-incident and change follow-through
Security scoping

Review the boundary for your target service.

Map the deployment, enforcement points, evidence needs, provider roles, recovery behaviour, and residual risk.

Scope a security review