Security Settings
Security Settings
Protect your Gail workspace with comprehensive security controls.
Authentication
Password Requirements
Configure password policy for your workspace:
To update:
- Go to Settings → Security → Password Policy
- Configure requirements
- Save changes
Multi-Factor Authentication (MFA)
Add an extra layer of security:
Supported Methods:
- Authenticator app (Google, Authy, etc.)
- SMS (less secure, not recommended)
- Hardware keys (YubiKey, etc.)
Enabling MFA:
- Go to Settings → Security → MFA
- Click Enable MFA
- Scan QR code with authenticator app
- Enter verification code
- Save backup codes securely
Requiring MFA for Team:
- Go to Settings → Security → MFA
- Enable Require MFA for all team members
- Set grace period for setup
- Save
Single Sign-On (SSO)
SSO is available on Enterprise plans.
Integrate with your identity provider:
- Okta
- Azure AD
- Google Workspace
- OneLogin
- Custom SAML 2.0
Session Management
Session Timeout
Configure automatic logout:
Active Sessions
View and manage active sessions:
- Go to Settings → Security → Sessions
- See all active sessions (device, location, time)
- Click Revoke to end a session
Force Logout
End all sessions for your account:
- Click Logout All Sessions
- Confirm
API Security
API Keys
Manage API keys at Settings → API Keys:
Creating Keys:
- Click Create API Key
- Name the key (e.g., “Production Server”)
- Set permissions (full or restricted)
- Set expiration (optional)
- Copy the key securely
API keys are shown only once. Store them securely.
Rotating Keys:
- Create a new key
- Update your applications
- Delete the old key
Key Permissions:
- Full Access - All API operations
- Read Only - GET requests only
- Custom - Specific endpoints only
IP Allowlisting
Restrict API access to specific IPs:
Rate Limiting
Default rate limits:
Contact support for increased limits.
Data Security
Encryption
All data is encrypted:
- In Transit - TLS 1.3
- At Rest - AES-256
Data Residency
Data residency options available on Enterprise plans.
Choose where your data is stored:
- United States
- European Union
- Asia Pacific
Data Retention
Configure how long data is kept:
Data Export
Export all your data:
- Go to Settings → Security → Data Export
- Click Request Export
- Receive download link via email
Data Deletion
Request permanent deletion:
- Go to Settings → Security → Data Deletion
- Select data types to delete
- Confirm deletion request
- Data is permanently removed within 30 days
Audit Logging
What’s Logged
All significant actions are logged:
- Authentication events (login, logout, failed attempts)
- Configuration changes
- Data access (call recordings, exports)
- Team management (invites, role changes)
- API usage
Viewing Audit Logs
- Go to Settings → Security → Audit Log
- Filter by date, user, or action type
- Export logs for analysis
Log Retention
Compliance
SOC 2 Type II
Gail maintains SOC 2 Type II certification. Request our report at security@meetgail.com.
HIPAA
HIPAA compliance available on Enterprise plans with BAA.
For healthcare customers:
- Contact sales for HIPAA-compliant plan
- Sign Business Associate Agreement (BAA)
- Enable HIPAA controls
GDPR
For EU data subjects:
- Data processing agreement available
- Right to access/delete honored
- Data portability supported
PCI DSS
Gail does not store payment card data. Call recordings containing card numbers should be redacted.
Security Notifications
Email Alerts
Receive alerts for:
- New device login
- Password changes
- Failed login attempts
- API key creation
- Team member changes
Configure Notifications
- Go to Settings → Notifications
- Select security events
- Choose notification method
- Save
Security Best Practices
For Administrators
- Enable MFA for all team members
- Use SSO when available
- Review audit logs regularly
- Rotate API keys periodically
- Use IP allowlisting for APIs
For Team Members
- Use strong, unique passwords
- Enable MFA on your account
- Don’t share credentials
- Log out of shared computers
- Report suspicious activity
Incident Response
Reporting Security Issues
If you discover a security vulnerability:
- Email: security@meetgail.com
- Do not disclose publicly until resolved
- We’ll acknowledge within 24 hours
In Case of Breach
If you suspect unauthorized access:
- Change your password immediately
- Revoke all API keys
- Review audit logs
- Contact support@meetgail.com
- Enable additional security controls
Next Steps
- Team Management - Manage team access
- Billing & Usage - Review account settings