Skip to content
Next cohort: applications open Apply now →
GrowGlobal24

Security Practices

We keep security practical and honest. Here is what we do, what we do not claim, and how to reach us.

What we claim, and what we do not

GrowGlobal24 does not currently hold SOC 2 or ISO 27001 certification, and we do not claim any. We are an advisory and coordination service, and we prefer to describe our real practices rather than borrow badges we have not earned. If we commission an independent audit in future, we will say so plainly and share the resulting report on request.

Our practices

  • Data minimisation: we ask for the information needed to scope your expansion and nothing more. Please do not send passwords, card numbers or identity documents by email.
  • Least access: only the people working on your scope see your briefing materials, and access ends when the engagement ends.
  • Strong authentication: accounts used for company email and documents are protected with multi-factor authentication.
  • Encrypted channels: this website is served over HTTPS, and we use encrypted email and document sharing where available.
  • Vendor care: we choose the tools we use with data protection in mind and review them periodically.

This website

This is a static website. It has no client portal or sign-in at present, no user accounts and no database of visitor information. Forms open your own email application, so nothing is transmitted to us until you choose to send the message. See the Privacy Policy for details of what your browser stores locally.

Regulated work and third parties

Banking, payroll, tax filing and legal filings are carried out by independent licensed providers that you contract with directly. Those providers operate under their own security controls and regulatory obligations. We can help you ask the right questions during selection, such as where data is hosted, who has access, and how incidents are reported.

Reporting a vulnerability or concern

If you believe you have found a security issue affecting this website or our services, please email [email protected]. Include a description, steps to reproduce and any relevant URLs. Please give us a reasonable opportunity to investigate before disclosing publicly, and avoid accessing data that is not yours. We will acknowledge reports and keep you informed as we work on them.

Requests for assurance information

Procurement and risk teams are welcome to ask for a summary of our practices or to raise a security questionnaire. We will answer accurately, including where the honest answer is that a control is not yet formalised. Write to [email protected] and tell us what your team needs.

This page describes practices, not a guarantee, and it is not legal advice.

Ready to plan your next market?

Tell us where you want to go and when. We reply with a scoped plan and the next steps — no obligation.