Content for more than 9,000 brands is managed in Gain. We don't take that responsibility lightly.
Gain runs on AWS, stores and processes all data in the United States, encrypts it in transit and at rest, and connects to the networks you publish to without ever storing your passwords. You rely on us to protect your data and the reputations of your brands and their customers. Here is exactly how we do it.
Gain's main infrastructure is hosted and managed entirely within Amazon's secure data centers using AWS. Those data centers are ISO 27001 and FISMA certified, with multiple layers of physical protection.
Managed network firewalls provide automatic DDoS mitigation, spoofing and sniffing protection, and automatic blocking of port-scanning attempts. Gain runs inside its own isolated cloud environment.
All of Gain's data is stored and processed in the United States. Data is encrypted in transit using SSL everywhere, and our databases are encrypted at rest.
Passwords are stored using the PBKDF2 algorithm with a SHA256 hash, individual random salting, and multiple hashing iterations.
Gain retains your data by default when you cancel, in case you decide to reactivate — and you can request complete deletion from our systems at any time.
We don't hand data to law enforcement unless a law, court order, or regulation compels us, or it's needed to establish or defend legal rights or protect someone's vital interests. To date, Gain has never received such an order.
Our product architecture keeps content for different brands completely separate. Your client will never see another client's content, no matter how many brands you manage under one account.
Permission-based access covers everyone in your collaboration circle. You control what each person can see and do, per brand.
Every user can enable two-step verification for an extra layer of account protection.
External reviewers approve content through a secure link sent to their email, without creating an account or a password of their own.
Gain follows web security best practices and is constantly tested against the latest vulnerabilities and attacks outlined in the OWASP Top Ten and others. Every component of the application stack is kept current with security updates.
We maintain a bug bounty program, hiring security researchers to run penetration tests and report anything they find.
Connections to social networks like Facebook, X (Twitter), Instagram and LinkedIn use each network's official authentication APIs and best practices.
We have never used social APIs in ways that violate the networks' terms of service, and never will.
Gain uses Stripe for all billing and payment functions. Stripe is audited by a PCI-certified auditor and certified to PCI Service Provider Level 1, the most stringent level available in the payments industry.
We have strict procedures for responding to security incidents. On discovery of a breach, customers are alerted immediately and we provide constant public updates on impact and mitigation. To date, Gain has had no major security incidents.
Our support team is available for live help and expedited solutions.
Reliability, battle-tested.
Six years of real-life experience under load. We monitor performance under heavy traffic constantly, so Gain stays responsive no matter how many people are on it.
Check live system status any time at status.gainapp.com.
Your approval record is part of your security posture.
A lot of content risk has nothing to do with hackers. It comes from content that publishes before sign-off, or a file that reaches the public without clearing legal review. Gain handles this in the structure of the product: content publishes only after it clears its approval workflow, and every decision is time-stamped and downloadable.
Teams that need sign-off before publishing keep that record as their audit trail. See how the record works →
Quick answers
All of Gain's data is stored and processed in the United States, hosted and managed within Amazon Web Services data centers. Those data centers are ISO 27001 and FISMA certified, with multiple layers of physical protection.
Yes. Every user can enable two-step verification (also called two-factor authentication) for an extra layer of protection. It comes alongside permission-based access for everyone in your collaboration circle, and complete separation between brands. SSO is available on the Enterprise plan.
No. Connections to Facebook, X (Twitter), Instagram, LinkedIn and the rest use each network's official authentication APIs. Gain never sees or stores those passwords and will never ask you for them directly.
User passwords are stored using the PBKDF2 algorithm with a SHA256 hash, individual random salting, and multiple hashing iterations. Nobody at Gain can read them.
Yes. Gain retains your data by default after cancellation in case you reactivate, and you can request complete deletion from our systems at any time. See the Privacy Policy for retention details.
To date, Gain has had no major security incidents and has never received an order for customer data from a law enforcement organization. We only hand over data where a law, court order, or regulation compels us, to establish or defend legal rights, or to protect someone's vital interests.
Gain's infrastructure runs in AWS data centers certified to ISO 27001 and FISMA. For Gain's own compliance documentation, download the Security and Reliability Overview, or contact us any time with security-related questions. We actually like talking about this.
Download the full Security and Reliability Overview, or write to us — we actually like talking about this.
Enterprise requirements? Covered.
SSO login, uptime SLAs, contract billing, volume plans, and approval training for your stakeholders all come with the Enterprise plan.