Gridstate

Review security and trust

Find Gridstate security controls, service status, subprocessors, retention limits, and procurement contacts.

Gridstate publishes the information that a technical or procurement review needs before purchase.

Security

The security and trust page lists current access controls, API-key storage, database isolation, service providers, and assurance limits.

Gridstate does not claim a security certification or independent penetration test for the full service. The trust page states this limit directly.

Send security reports to tyler@grayhavenindustries.com. Do not include passwords or API keys.

Status and uptime

The status page makes a direct request to the production API. It shows the active release and published incidents.

Self-serve plans do not include a contractual uptime service level. A signed order form can include different terms.

Subprocessors and data processing

The privacy policy names each service provider, its purpose, and the customer data that it processes.

Email tyler@grayhavenindustries.com to request the Gridstate data processing addendum.

Retention and deletion

The privacy policy gives the retention limit for account data, API audit events, revoked key hashes, support email, billing records, and backups.

Gridstate acknowledges a verified privacy request within ten business days. Gridstate completes a verified deletion request within 30 days unless law requires more time.

Grayhaven Industries operates Gridstate from Oklahoma City, Oklahoma. The terms of service identify the self-serve contracting party and governing law.

On this page