Skip to Content
Project DocsSecurity & PrivacySecurity Baseline

Security Baseline

Use this page as a practical minimum baseline before you scale traffic or add devices.

Objective

Build a stable setup that:

  • survives routine network instability;
  • limits accidental data exposure;
  • can be audited quickly by one operator.

Minimum controls

ControlRequirementVerification
Client versionCurrent GigaTap client or supported profile clientCheck app version in settings
Kill switchEnabled when supportedDrop uplink and verify traffic stop
DNS policyProvider DNS onlyLeak test from two independent tools
Time syncNTP synchronizedDevice drift less than 2 seconds
Profile hygieneDedicated profile per use-caseNo profile reuse across personal and sensitive activity

Client hardening checklist

  • Disable auto-join for unknown Wi-Fi networks.
  • Disable split tunneling unless explicitly required.
  • Use a separate browser profile for sensitive sessions.
  • Keep background apps to a minimum during sensitive work.
  • Do not store profile files in cloud-synced folders.

Monthly audit routine

  1. Rotate profile credentials and revoke stale ones.
  2. Re-run DNS/IP leak checks on each active device.
  3. Verify firewall rules and local exceptions.
  4. Export a short audit log with date, device, and result.

Incident first response

If you suspect a profile compromise:

# 1) immediately disable current session/profile # 2) rotate credentials in GigaTap app or support flow # 3) generate a new profile # 4) re-import profile on trusted device only

Then review account access history and remove unknown devices.

Last reviewed: 2026-05-26.

Last updated on