Internet Security
Impersonation of companies is increasingly common, and technology consultancies are a frequent target: someone posing as us gains credibility with our clients. This page explains how we actually communicate and what to do when something does not add up.
How we communicate
- Our emails always come from the
@galde.appdomain. Any lookalike — with hyphens, a different extension, or one letter changed — is not ours. - We will never ask by email, phone or messaging for your passwords, one-time codes, access keys to your systems, or full bank card details.
- We will never notify a change of bank account by email alone. If it ever changed, we would confirm it by telephone, calling a number you already held.
- Our team identifies itself by full name and can be verified on Galde's corporate LinkedIn profile.
Signs that something is wrong
- Disproportionate urgency: "today", "before the bank closes".
- An unexpected change of bank account or payment terms.
- A sender that resembles ours without being identical.
- Links whose real destination does not match the visible text.
- Unexpected attachments, especially compressed files or documents with macros.
- Requests for remote access to your machines that you did not initiate.
What to do
- Do not reply and do not click, and do not forward the message to colleagues.
- Verify through another channel. Call (+34) 688 86 73 94 or write to info@galde.app in a new message, never by replying to the suspicious one.
- Keep the evidence. Do not delete the email: it is what allows it to be reported.
- Let us know at info@galde.app.
If you believe you have disclosed credentials or made a payment, contact your bank immediately and, in Spain, the National Cybersecurity Institute (INCIBE) on the free number 017.
Practices we recommend
- Enable two-step verification on corporate email.
- Use a password manager and do not reuse credentials across services.
- Put in place an internal double-verification procedure for any change to a supplier's bank details — including ours.
- Keep systems and browsers up to date.
Our commitments
We apply technical and organisational measures to protect the information you entrust to us: encryption in transit, least-privilege access control, regular backups and permission reviews.
Responsible disclosure
If you find a vulnerability in our systems, we would be grateful if you reported it to info@galde.app before making it public. We undertake to acknowledge receipt within 72 hours, keep you informed of progress, and take no legal action against anyone researching in good faith without degrading the service or accessing third-party data.
Last updated: 14 September 2026