Skip to content

Security commitments

Security at Gluu

Security and trust are fundamental to Gluu's mission. We maintain an information security program designed to identify and manage security risks, protect sensitive information, and support the secure and reliable delivery of our products and services.

Our security commitments

  • Applying secure software development and change-management practices
  • Protecting access to systems and information through appropriate authentication and authorization controls
  • Encrypting sensitive information in transit and, where applicable, at rest
  • Monitoring systems and addressing identified security vulnerabilities
  • Maintaining incident response, business continuity and disaster recovery processes
  • Conducting periodic risk assessments and reviewing the security practices of relevant service providers
  • Providing security and privacy awareness training to personnel
  • Continually improving controls as technologies, risks and regulatory expectations evolve

Open-source security

Gluu believes transparency and open-source development produce stronger, more trustworthy software. Gluu and the Janssen Project support responsible vulnerability management and follow applicable vulnerability disclosure and remediation processes.

Responsible disclosure

Security researchers and customers who believe they have identified a vulnerability affecting a Gluu product or service should report it privately to security@gluu.org.

Please do not publicly disclose a suspected vulnerability until Gluu has had a reasonable opportunity to investigate and address it.

Compliance and assurance

Gluu regularly evaluates its security and compliance practices against applicable contractual, regulatory and industry requirements. Additional security or compliance information may be made available to customers and prospective customers upon appropriate request and, where necessary, under a confidentiality agreement.

Security-related questions