Galvafy Studio & Academy
Trust & Security
Answers for HR Directors and compliance buyers: where employee and learning data lives, who can see it, and what happens if something goes wrong.
Last updated: July 20, 2026
Who this page is for
Before rostering employees into Galvafy Academy (or inviting creators into Studio), buyers reasonably ask: Where is our compliance and user data stored, and what happens in a breach or hack? This page is that answer. It covers both Studio and Academy.
Full consumer-facing privacy detail: Privacy Policy. Security contact: security@galvafy.com.
Where data is stored
Application & learning records
Galvafy Studio and Academy run on DigitalOcean application hosts in the United States. Primary product data — including user profiles linked to the workspace, course content metadata, enrollments, progress, quiz results, certificates, assignments, and related compliance-oriented learning history — is stored in our managed PostgreSQL database in that same US operational footprint.
Files and media
Uploaded assets, SCORM/xAPI packages, thumbnails, and media are stored in S3-compatible object storage. Default configuration uses a US region (commonly us-east-1-style targeting unless your deployment overrides it).
Identity & billing
Authentication and subscription checkout are handled by Galvafy Core and payment processors (Stripe). Entitlement and identity data therefore also exist in those systems under Galvafy’s production controls.
Who can see employee / learner data
- Workspace isolation — content and learner records belong to a workspace. Other customers cannot access your workspace data through the product.
- Role-based access — Owners, Admins, creators, and learners see only what their role and assignments allow (for example, managers see completion for people they are permitted to view; learners see their own progress).
- Galvafy staff — access is limited to operational need (support, security response, reliability). We do not use customer learner transcripts for unrelated marketing.
- AI vendors — when a user invokes an AI feature, the prompts and necessary context for that request are processed by the model provider to fulfill the feature. Usage is metered for plan enforcement.
Breach or security incident posture
If we become aware of a security incident affecting customer data, our operating posture is to:
- Contain and investigate promptly
- Assess impact to customer and learner data
- Notify affected customer contacts without undue delay, with what we know, what data may be involved, and remediation steps underway
- Remediate root cause and strengthen controls
- Document the incident for continuous improvement and future audit readiness
Report a suspected vulnerability or incident to security@galvafy.com.
Subprocessors (high level)
- DigitalOcean — application hosting and related infrastructure
- S3-compatible storage — media and content packages
- Galvafy Core — identity and SaaS billing orchestration
- Stripe — payment processing
- Anthropic / OpenAI (and similar) — AI generation and assistance features
- Email and observability providers when enabled in an environment
Retention & deletion
Learning and account data are retained while the customer uses Galvafy and for backup / legal hold periods afterward. Individuals can export data and request deletion from in-product Settings. Organization offboarding and broader deletion requests can be directed to privacy@galvafy.com.
SOC 2 roadmap
We are not claiming SOC 2 Type II attestation today. We maintain a roadmap so buyers can see direction of travel.
Controls in place today (snapshot)
- Centralized authentication via Galvafy Core (no local SSO re-implementation)
- Workspace and role-based authorization in Studio and Academy
- TLS for data in transit on public endpoints
- Server-side entitlement and usage enforcement (not client-trusted)
- Operational deploy controls and application error monitoring when configured
- Customer data export and account deletion paths in product settings
Near-term (next 1–2 quarters)
- Formalize written security policies and vendor inventory for audit readiness
- Document access reviews, backup/restore verification, and incident runbooks
- Publish a living subprocessor list and expand trust FAQ for procurement
Next (enterprise motion)
- Engage an independent auditor for SOC 2 Type I, then Type II
- Align enterprise SSO (SAML/SCIM) and HRIS work with customer demand
This roadmap is informational and may change as product and customer priorities evolve.