GigMatch
Security

How GigMatch protects employee data

GigMatch is built so employees can use the benefit privately and securely, and so the organizations that offer it can trust where the data lives.

For technical questions, your security team can reach us at security@gigmatch.com.

Encryption

All traffic between the GigMatch app or admin portal and our backend is encrypted with TLS 1.2 or higher. Data at rest is encrypted in our managed PostgreSQL database using managed keys, with encrypted backups and encrypted object storage for any files.

Authentication and the app

Employees sign in with Apple, Google, or email and password, following current NIST password guidance. The GigMatch app runs on the employee's own iOS or Android device and is distributed through the App Store and Google Play, so each release passes Apple's and Google's review before it reaches anyone. There is nothing to install on company-managed devices and no IT involvement required on the employer's side.

Data minimization

GigMatch collects only what it needs to deliver the product. For each registered employee, that is:

We do not collect:

Privacy and data sharing

We do not sell user data. And we do not share an individual employee's data with the employer who sponsors the benefit — employers see only aggregate, anonymized numbers, never anything tied to a specific person. An employee's participation and answers stay private inside GigMatch.

We share data with vendors only as necessary to run the service — cloud hosting, email delivery, identity, analytics, and error reporting — each governed by a Data Processing Agreement. The full vendor list is available on request.

Compliance and audits

SOC 2 compliance is in progress. CCPA disclosures are covered in the GigMatch Privacy Policy. GigMatch does not handle protected health information and is not HIPAA-aligned. We can provide additional documentation — architecture overview and full vendor list — under NDA on request.

Incident response

We monitor production systems for anomalous activity and unusual data access. If we identify a security incident:

Vulnerability disclosure

If you or your security team identifies a vulnerability in our app or backend, please report it to security@gigmatch.com. We acknowledge legitimate reports within 48 hours, share a remediation timeline within one week of triage, and track the report through resolution. We do not pursue legal action against good-faith security researchers.

Questions

Technical security questions: security@gigmatch.com.
Everything else: hello@gigmatch.com.