Security at GymStack
The measures that protect your studio's business data and your members' personal data.
Practices at a glance
Encryption
All traffic uses TLS 1.2+; data is encrypted at rest with AES-256. Backups are encrypted with separate keys.
Infrastructure
Hosted on ISO 27001-certified cloud providers in Türkiye and the EU, with network isolation between customers.
Access control
Role-based permissions, mandatory 2FA for staff and GymStack personnel, and audit logs for sensitive actions.
Payments
Card payments run through PCI DSS Level 1 providers. Full card numbers never reach GymStack servers.
Backups & recovery
Encrypted daily backups with point-in-time recovery; restore drills run every quarter.
Monitoring
24/7 infrastructure monitoring, anomaly alerts, and centralized logging with restricted access.
07Organizational measures
Access to production is limited to a small, named engineering group under least-privilege rules; access rights are reviewed quarterly.
All personnel sign confidentiality agreements and complete annual security and KVKK awareness training.
08Incident response
We maintain a written incident-response plan. If an incident affects personal data, we notify the affected gyms and the authorities within the statutory deadlines (72 hours under the KVKK/GDPR frameworks), including the facts, the impact, and the countermeasures taken.
09Responsible disclosure
Found a vulnerability? E-mail [email protected] with steps to reproduce. We confirm receipt within 48 hours and keep you updated until resolution.
We do not pursue good-faith research that respects member data and service availability.