Security at Gusto

We take data security and privacy extremely seriously. Our approach to product development ensures our customers are in control of their data and that their information is safe.

Want to report a security vulnerability? Jump to our Bug Bounty program

Learn more about preventing fraud on your Gusto account at the Gusto Help Center .

Data security

Data encryption

Data in transit All data transferred between the user’s browser and Gusto’s servers is encrypted in transit. Gusto uses TLS v1.2

Data at rest Data is encrypted at rest in AWS using AES-256 key encryption.

Data center security

Data center provider Gusto uses Amazon Web Services (AWS) to host its production servers, databases, and supporting services.

Multi-region Gusto uses a multi-region setup for its infrastructure. The principal region for running the application is AWS region US-West-2 (Oregon), with AWS region US-East-1 (Virginia) for its backup.

Data availability

Backups

Gusto's production systems and data are backed up on a regular basis. We run through a checklist to verify data is recorded and usable. Backups are tested on a periodic basis.

Status page

Gusto service statuses, maintenance updates, and any incidents affecting our users are documented and available at gusto.statuspage.io.

Application security

Development security

Access controls Access to Gusto's systems is limited based on employee roles and responsibilities. The principle of least privilege is enforced.

Testing and review All changes to our application are subject to peer review and testing before being merged.

Separate environments Gusto maintains segregated testing, development, and production environments.

Vulnerability management

Penetration testing Gusto’s security team uses third parties to conduct penetration tests to identify deficiencies in the system that may affect critical assets.

Vulnerability scanning Gusto uses third-party security tools to continuously scan our applications, systems, and infrastructure for security risks and vulnerabilities.

Code analysis Gusto's code repositories are regularly scanned for security issues using static code analysis.

Bug bounty Gusto offers rewards for user-submitted bugs found in our API. For more information, check out the Bug Bounty Program section at the bottom of the page.

Product security

Authentication

Multi-Factor Authentication Gusto allows you to add an extra layer of security to your account by enabling two-step verification, also called two-factor authentication. This reduces the risk of having your account accessed by anyone else.

Manager permissions With Gusto’s Complete plan, admins can provide limited-access permissions to certain accounts.

Fraud monitoring

Transaction monitoring Gusto proactively monitors customer accounts to help prevent fraudulent transactions.

Learn more about product security here.

People security

Security awareness

Dedicated team Gusto has a dedicated security team to enforce secure practices and respond to security incidents quickly and efficiently.

Policies Gusto maintains a robust set of security policies that are updated periodically to meet the demand of an evolving security environment. Policies are communicated to employees and available for review at any time.

Training All Gusto employees are required to complete security training. Gusto's security team provides continuous education on emerging security threats, and communicates updates with employees regularly.

Employee checks

Background checks Gusto performs background checks for potential candidates before hiring.

New-hire reviews All new hires are required to sign and acknowledge Gusto’s information security policy and confidentiality agreements upon joining the team.

Information security

SOC

SOC Reports Gusto maintains SOC 1 and SOC 2 reports, which are updated annually. Customers can access these reports via our Trust Center after filling out a nondisclosure agreement. Learn more from the AICPA about SOC reports. If you have any questions, please email our security team.

Click here to sign our nondisclosure agreement and get access to our report documentation.

HIPAA

HIPAA guidelines We follow HIPAA guidelines to safeguard our customers’ protected health information (PHI). Additionally, we maintain business associate agreements (BAAs) between employers and Gusto, along with any third parties, like insurance companies. Read more.

Bug bounty program

Help keep Gusto safe.

If you discover a security issue within Gusto’s API, submit a bug report with a detailed description of the issue and steps to reproduce it. Once your bug is confirmed and validated, we’ll add you to our hall of fame.

Visit our Bugcrowd page to learn about the types of bugs we’re looking for, and view our bug bounty hunter hall of fame.