Security Baseline
Use this page as a practical minimum baseline before you scale traffic or add devices.
Objective
Build a stable setup that:
- survives routine network instability;
- limits accidental data exposure;
- can be audited quickly by one operator.
Minimum controls
| Control | Requirement | Verification |
|---|---|---|
| Client version | Current GigaTap client or supported profile client | Check app version in settings |
| Kill switch | Enabled when supported | Drop uplink and verify traffic stop |
| DNS policy | Provider DNS only | Leak test from two independent tools |
| Time sync | NTP synchronized | Device drift less than 2 seconds |
| Profile hygiene | Dedicated profile per use-case | No profile reuse across personal and sensitive activity |
Client hardening checklist
- Disable auto-join for unknown Wi-Fi networks.
- Disable split tunneling unless explicitly required.
- Use a separate browser profile for sensitive sessions.
- Keep background apps to a minimum during sensitive work.
- Do not store profile files in cloud-synced folders.
Monthly audit routine
- Rotate profile credentials and revoke stale ones.
- Re-run DNS/IP leak checks on each active device.
- Verify firewall rules and local exceptions.
- Export a short audit log with date, device, and result.
Incident first response
If you suspect a profile compromise:
# 1) immediately disable current session/profile
# 2) rotate credentials in GigaTap app or support flow
# 3) generate a new profile
# 4) re-import profile on trusted device onlyThen review account access history and remove unknown devices.
Last reviewed: 2026-05-26.
Last updated on