Passwordless sign-in
We never store passwords. You sign in with a one-time code sent to your email, or with Google Sign-In. No password means nothing to leak or reuse.
Encryption in transit
All traffic between your browser and Gleon OS travels over HTTPS/TLS. Data moving between you and our servers is encrypted end-to-end on the wire.
Secure payments
Payments are processed by Cashfree, a PCI-DSS compliant Indian payment gateway. Gleon OS never sees or stores your full card or UPI credentials.
Session protection
Sessions use short-lived access tokens with automatic refresh and expiry. If a session expires, you are asked to sign in again before continuing.
01 Account & authentication
Your account is the front door to Gleon OS, so we keep that door strong and simple:
- Email OTP: a 6-digit, time-limited code is sent to your email to verify it is really you. Codes expire after a few minutes.
- Google Sign-In: you may also sign in with your Google account using Google's own secure flow. We receive only a verified sign-in token, never your Google password.
- No stored passwords: because Gleon OS is passwordless, there is no password database to breach.
- Rate limiting: repeated sign-in and code attempts are throttled to slow down abuse.
02 Data in transit & at rest
We protect your data both while it moves and while it is stored:
- In transit: every connection to Gleon OS uses HTTPS/TLS. Plain, unencrypted HTTP is upgraded automatically.
- At rest: your workspace data, memories, and account records are stored with our managed infrastructure providers using their encryption and access controls.
- Least access: internal access to production data is limited to what is necessary to operate and support the service.
03 Payments & billing
Gleon OS uses Cashfree as its payment gateway for all paid plans and credit purchases.
- Card, UPI, and netbanking details are entered on Cashfree's secure, PCI-DSS compliant systems - not on Gleon OS.
- Gleon OS stores only what is needed to manage your plan and credits, such as your plan name, order references, and credit balance.
- You must be signed in to purchase or upgrade a plan; checkout is never available without authentication.
04 Infrastructure
Gleon OS runs on established cloud infrastructure with India-region data handling where applicable:
- Application & APIs are hosted on managed cloud platforms with isolated environments.
- Databases and caches are operated by managed providers with their own security, backups, and access controls.
- Secrets and API keys are stored in a secrets manager, never hard-coded into the app you load in your browser.
05 Your responsibilities
Security is a shared effort. You can help keep your account safe by:
- Keeping access to your email and Google account secure, since those are how you sign in.
- Signing out on shared or public devices.
- Never sharing one-time codes with anyone - Gleon OS staff will never ask for your OTP.
06 Reporting a vulnerability
If you believe you have found a security issue in Gleon OS, we want to hear from you. Please email us with details and steps to reproduce, and allow us reasonable time to investigate and fix the issue before any public disclosure. We appreciate responsible disclosure.
Security contact
Email: hello@gleon.cloud
Gleon Cloud - Rajkot, Gujarat, India
For data and privacy requests, see our Privacy Policy.