Content for more than 9,000 brands is managed in Gain. We don't take that responsibility lightly.

Gain runs on AWS, stores and processes all data in the United States, encrypts it in transit and at rest, and connects to the networks you publish to without ever storing your passwords. You rely on us to protect your data and the reputations of your brands and their customers. Here is exactly how we do it.

99.95%
average platform uptime
3M+
posts published through Gain
Zero
major security incidents to date
US
all data stored & processed stateside
Infrastructure

Gain's main infrastructure is hosted and managed entirely within Amazon's secure data centers using AWS. Those data centers are ISO 27001 and FISMA certified, with multiple layers of physical protection.

Managed network firewalls provide automatic DDoS mitigation, spoofing and sniffing protection, and automatic blocking of port-scanning attempts. Gain runs inside its own isolated cloud environment.

Data security

All of Gain's data is stored and processed in the United States. Data is encrypted in transit using SSL everywhere, and our databases are encrypted at rest.

Passwords are stored using the PBKDF2 algorithm with a SHA256 hash, individual random salting, and multiple hashing iterations.

Privacy

Gain retains your data by default when you cancel, in case you decide to reactivate — and you can request complete deletion from our systems at any time.

We don't hand data to law enforcement unless a law, court order, or regulation compels us, or it's needed to establish or defend legal rights or protect someone's vital interests. To date, Gain has never received such an order.

Permissions

Our product architecture keeps content for different brands completely separate. Your client will never see another client's content, no matter how many brands you manage under one account.

Permission-based access covers everyone in your collaboration circle. You control what each person can see and do, per brand.

Sign-in

Every user can enable two-step verification for an extra layer of account protection.

External reviewers approve content through a secure link sent to their email, without creating an account or a password of their own.

Best practices

Gain follows web security best practices and is constantly tested against the latest vulnerabilities and attacks outlined in the OWASP Top Ten and others. Every component of the application stack is kept current with security updates.

We maintain a bug bounty program, hiring security researchers to run penetration tests and report anything they find.

API integrations

Connections to social networks like Facebook, X (Twitter), Instagram and LinkedIn use each network's official authentication APIs and best practices.

We have never used social APIs in ways that violate the networks' terms of service, and never will.

Payments

Gain uses Stripe for all billing and payment functions. Stripe is audited by a PCI-certified auditor and certified to PCI Service Provider Level 1, the most stringent level available in the payments industry.

Support & incident response

We have strict procedures for responding to security incidents. On discovery of a breach, customers are alerted immediately and we provide constant public updates on impact and mitigation. To date, Gain has had no major security incidents.

Our support team is available for live help and expedited solutions.

Reliability, battle-tested.

Six years of real-life experience under load. We monitor performance under heavy traffic constantly, so Gain stays responsive no matter how many people are on it.

Check live system status any time at status.gainapp.com.

Over 100,000 posts published per month
More than 3 million posts sent to social networks to date. Some single accounts handle over 6,000 posts a month, with thousands of users under one account.
Every post pre-checked before it publishes
Content is automatically validated against each network's specs, so errors surface before publishing rather than after.
99.95% average uptime
Maintenance downtime is communicated weeks in advance. Enterprise customers get SLAs guaranteeing reliability and support levels — ask our support team.
Facebook native scheduling, optionally
For Facebook you can publish through Gain's engine or hand scheduling to Facebook's own. Edits made in Gain still flow through to Facebook's scheduler.

Your approval record is part of your security posture.

A lot of content risk has nothing to do with hackers. It comes from content that publishes before sign-off, or a file that reaches the public without clearing legal review. Gain handles this in the structure of the product: content publishes only after it clears its approval workflow, and every decision is time-stamped and downloadable.

Teams that need sign-off before publishing keep that record as their audit trail. See how the record works →

What auditors ask · what Gain answers
"Who approved this?"
The named approver, with a time stamp.
"Did they approve what actually went live?"
Approvals attach to the exact content that was reviewed. If someone edits it after approval, the workflow starts again.
"Could it have published without sign-off?"
Publishing is gated on the workflow, so content cannot go out until it clears approval.
"Can we have it in writing?"
The full history exports as a time-stamped report, for a single item or an entire client.

Quick answers

All of Gain's data is stored and processed in the United States, hosted and managed within Amazon Web Services data centers. Those data centers are ISO 27001 and FISMA certified, with multiple layers of physical protection.

Yes. Every user can enable two-step verification (also called two-factor authentication) for an extra layer of protection. It comes alongside permission-based access for everyone in your collaboration circle, and complete separation between brands. SSO is available on the Enterprise plan.

No. Connections to Facebook, X (Twitter), Instagram, LinkedIn and the rest use each network's official authentication APIs. Gain never sees or stores those passwords and will never ask you for them directly.

User passwords are stored using the PBKDF2 algorithm with a SHA256 hash, individual random salting, and multiple hashing iterations. Nobody at Gain can read them.

Yes. Gain retains your data by default after cancellation in case you reactivate, and you can request complete deletion from our systems at any time. See the Privacy Policy for retention details.

To date, Gain has had no major security incidents and has never received an order for customer data from a law enforcement organization. We only hand over data where a law, court order, or regulation compels us, to establish or defend legal rights, or to protect someone's vital interests.

Gain's infrastructure runs in AWS data centers certified to ISO 27001 and FISMA. For Gain's own compliance documentation, download the Security and Reliability Overview, or contact us any time with security-related questions. We actually like talking about this.

Want the nitty-gritty?

Download the full Security and Reliability Overview, or write to us — we actually like talking about this.

Download PDF

Enterprise requirements? Covered.

SSO login, uptime SLAs, contract billing, volume plans, and approval training for your stakeholders all come with the Enterprise plan.