Security

Security evidence for your review.

Procurement teams should not have to take a vendor's word for anything. Here is what we hold, how we handle credentials, and where your responsibility begins.

ISO 27001 certified

Guni Innovations Pte. Ltd. holds ISO 27001 certification for its information security management system. The certificate and scope statement are available on request for your security review.

Legal entity
Guni Innovations Pte. Ltd.
UEN
202302437E
Jurisdiction
Singapore
Contact
dani@dataforgaio.com

Credential handling

API keys are displayed once at creation and stored hashed. Rotation and revocation are immediate and recorded.

Transport and storage

Traffic is encrypted in transit. Job data and receipts are stored under access controls tied to your workspace.

Access control

Account access is scoped per workspace, with multi-factor authentication for sign-in once auth is connected.

Operational practice

Change management, logging, and incident handling are governed by the certified management system.

Crawling conduct

We fetch only publicly reachable pages with a declared agent, respect robots directives, and never bypass access controls.

Documents on request

Certificate, scope statement, and DPA are provided for review during procurement.

Shared responsibility

We are responsible for

  • · Securing the service and the data it holds for you.
  • · Recording permission signals accurately and completely.
  • · Handling credentials so they cannot be retrieved after creation.
  • · Notifying you of security incidents affecting your workspace.

You are responsible for

  • · Keeping API keys secret and rotating them when exposed.
  • · Controlling who in your organization can access the workspace.
  • · Deciding whether your intended use of fetched content is lawful.
  • · Meeting obligations that apply to you as a data controller.
Answers

Security questions

Still unsure? Write to dani@dataforgaio.com or read the full FAQ.

Need documents for procurement?

Ask for the ISO 27001 certificate, scope statement, or a DPA and we will send them across.