G-P Gia Security and Privacy
Protecting your data is our top priority. Our commitment to data privacy and security is embedded in every part of our business.
Certifications & Compliance
At G-P, we're committed to keeping your HR compliance data safe. G-P is certified to ISO/IEC 42001, the international standard for Artificial Intelligence Management Systems (AIMS), ensuring safe, ethical, and responsible AI development. G-P is also SOC 2 certified, meaning we’ve met rigorous security standards. For Gia, we've implemented comprehensive security controls based on SOC 2 Type II principles, and we’re on a structured pathway to formal certification.
We provide transparency through our privacy and security center, where you can access our security policies, the results of our most recent penetration test, and regular updates on our certification progress.

Security & Protection
G-P provides a robust set of in-product data protection and admin controls to give you more visibility and control over your data. Enterprise admins can enable enterprise-grade security controls, including single sign-on (SSO) integration and audit logging.
- Encryption: All data encrypted at rest and in transit using industry-standard encryption.
- Roles & Permissions: Comprehensive access controls with role-based permissions and MFA.
- SSO (SAML): Seamless secure access with your existing identity provider.
- SCIM: Automate user provisioning for efficient access management.
- Audit logs: Complete visibility into user actions for compliance and security tracking (on request).
- Team Management: Set access permissions for your team. Ensure only the right roles have access to the data they need.
Data Privacy & Controls
G-P adheres to strict data privacy
regulations and guidelines to protect each individual user.
Data Confidentiality
Your queries and documents are kept separate from other users’ information. Your data remains confidential and is not shared or used by any third-party except for our trusted data processors who adhere to strict data privacy agreements.
Document Deletion
Users can submit formal data deletion requests at any time and we’ll permanently remove the specified data from our systems.
Data Retention
Data retention for AI is aligned with our broader data retention policies as described in customer agreements and documentation available on our security portal.
Frequently asked questions.
Is my data used to train Gia or shared with third parties?
No. We don’t train AI models on user inputs. In fact, we don’t train models. We use a RAG-based approach which grounds responses on G-P provided data, not user data. We have other robust measures in place to protect your information:
We maintain strict user data isolation to ensure your information is never accessible to other users. Each user has limited access enforced by application security processes and technology. We encrypt data both in transit and at rest.
We have strong governance standards for limiting access to user data within G-P, including specific access controls by data type.
We comply with various security standards, including ISO 42001, ISO 27001, CCPA, GDPR, and SOC2.
You can choose to omit personal data from your interactions with Gia. However, if you include personal data in a prompt or upload it, Gia may process that data in the course of the interaction. By using Gia you agree to the secure transfer, processing, and storage of your data as outlined in our terms and privacy policy.
Who can see my questions or conversations?
Your conversations with Gia are completely confidential. Access is limited to our authorized team members, who only view interactions when necessary for system improvements, enhancements, or troubleshooting. We never sell or share your personal information with third parties.
How does G-P prevent other users from accessing my uploads or sensitive information?
We ensure that user content – including chats and uploaded document files – are secure by implementing the following measures:
Strict data segregation: All user data is isolated based on user ID, so no user’s content is accessible to another.
No large language model (LLM) training: We don’t train an LLM with user data. We use a RAG-based approach which grounds responses on G-P provided data.
What’s G-P's data retention policy for AI?
Data retention for AI is aligned with our broader data retention policies described in customer agreements and documentation on our security portal. In addition to operational datastores, all chats are logged and audited to support ongoing quality improvement.
How does G-P use and store my data ?
G-P uses a multifaceted approach to safeguarding your information:
End-to-end encryption: Your data is encrypted at all stages of its journey. Only authorized parties with the correct decryption keys can access it. This prevents unauthorized interception and tampering.
Access limited to authorized personnel: Strict controls limit data access to essential personnel who require it to perform their job functions. This prevents unauthorized internal access and data leaks.
No third-party sharing: G-P doesn’t share your personal data with any unauthorized third parties.
Compliance with privacy regulations: G-P adheres to all applicable data privacy regulations, ensuring that your data is handled in a lawful and ethical manner.




