Skip to content
Security

How GigMatch protects employee data

GigMatch is built so employees can use the benefit privately and securely, and so the organizations that offer it can trust where the data lives.

For technical questions, your security team can reach us at security@gigmatch.com

  • Hosting: AWS, United States regions

  • Encryption in transit: TLS 1.2 or higher for all connections

  • Encryption at rest: database and backups encrypted with managed keys

  • Apps: iOS and Android, distributed through the App Store and Google Play

  • SOC 2: compliance in progress

Encryption

All traffic between the GigMatch app or admin portal and our backend is encrypted with TLS 1.2 or higher. Data at rest is encrypted in our managed PostgreSQL database using managed keys, with encrypted backups and encrypted object storage for any files.

Authentication and the app

Employees sign in with Apple, Google, or email and password, following current NIST password guidance. The GigMatch app runs on the employee's own iOS or Android device and is distributed through the App Store and Google Play, so each release passes Apple's and Google's review before it reaches anyone. There is nothing to install on company-managed devices and no IT involvement required on the employer's side.

Data minimization

GigMatch collects only what it needs to deliver the product. For each registered employee, that is:

  • Authentication identifiers (email, sign-in provider IDs)

  • Profile information the employee chooses to provide (name, contact info, zip code)

  • The stuff, interests, and skills used to generate gig matches

  • App usage and engagement data

We do not collect:

  • Government identifiers such as Social Security or driver's license numbers — they are not required to use GigMatch

  • Bank account or payment card information from employees — the employer pays the contract and employees pay nothing

  • Location data beyond zip code, unless the employee explicitly opts in to a location-based feature

Privacy and data sharing

We do not sell user data. And we do not share an individual employee's data with the employer who sponsors the benefit — employers see only aggregate, anonymized numbers, never anything tied to a specific person. An employee's participation and answers stay private inside GigMatch.

We share data with vendors only as necessary to run the service — cloud hosting, email delivery, identity, analytics, and error reporting — each governed by a Data Processing Agreement. The full vendor list is available on request.

Compliance and audits

SOC 2 compliance is in progress. CCPA disclosures are covered in the GigMatch Privacy Policy. GigMatch does not handle protected health information and is not HIPAA-aligned. We can provide additional documentation — architecture overview and full vendor list — under NDA on request.

Incident response

We monitor production systems for anomalous activity and unusual data access. If we identify a security incident:

  • We assess scope and severity within 24 hours

  • We notify affected customers within 72 hours where employee data may have been affected

  • We implement and verify remediation

  • We produce a post-incident report for affected customers within two weeks of resolution

Vulnerability disclosure

If you or your security team identifies a vulnerability in our app or backend, please report it to security@gigmatch.com. We acknowledge legitimate reports within 48 hours, share a remediation timeline within one week of triage, and track the report through resolution. We do not pursue legal action against good-faith security researchers.

Questions

Technical security questions: security@gigmatch.com.
Everything else: hello@gigmatch.com.