General FAQs
What is Garbo?
Garbo is a platform for real-time mobile system abstraction providing advanced analysis, introspection, and environment control. It is designed to empower investigation and defense teams with control, performance, and trust. Learn more in the Garbo Docs page: What is Garbo?
Who is Garbo for?
Garbo serves cybersecurity companies and forensic labs, government and defense organizations, research centers and universities, independent researchers, and institutional partners. See detailed audiences and use cases in: Audience.
What can Garbo do today?
Capability overviews are described under the capabilities section.
Which operating systems or devices are currently supported?
For the broader capabilities roadmap, refer to: Compatibility.
How does Garbo archieve high performance?
Garbo uses advance technology and architecture to minimize latency. You can find more in Scalability and Performance and in General Architecture.
How does Garbo handle information security and privacy?
Garbo implements strict data isolation, role-based access control and audit-ready logging. Development and deployment follow Security-by-Design and Privacy-by-Default with secure coding, peer reviews and automated vulnerability scanning. See: Information Security and Confidentiality.
Where is data processed and stored in cloud deployments?
Cloud deployments are configured under Google Cloud’s EU compliance framework, ensuring that data is processed and retained within the EEA in accordance with relevant EU data protection laws. Compliance monitoring and data retention follow Google Cloud Security and Data Protection standards, with plans for external audits and structured assessments.
While aligned with EU regulations, the framework is adaptable to meet additional international or regional compliance requirements as needed. See: Regulatory Compliance and Certifications.
How do I contact the team, report issues, or coordinate partnerships?
Use the institutional contact channels that appear in the page Institutional Contact.
What is Garbo’s approach to ethics and responsible use?
Garbo is designed for defensive and scientific purposes within lawful, controlled environments. Access management ensures use only for authorized activities, aligned with international cybersecurity and research ethics frameworks. See: Ethical and Responsible Use.
What certifications and regulatory frameworks does Garbo align with?
Garbo is certified under the Spanish National Security Framework (ENS) at its highest level (Categoría ALTA). Additionally, the platform is built to align with ISO 27001 and EU NIS2 principles, following ISO 9001 quality management practices. GDPR and ENISA guidelines are integrated into operational and security processes, with further external audits and structured assessments planned to ensure continuous compliance. See: Regulatory Compliance and Certifications.
Who is the Garbo report system intended for?
The channel is open to anyone involved with Garbo in a professional capacity—employees, external collaborators, partners or contractors—who needs to raise concerns about conduct, operations, or information handling that could affect the integrity of the project.
Can I remain anonymous when submitting a report?
Yes. The platform is configured using Globaleaks to avoid collecting identifying metadata unless you choose to provide it. Anonymous reports follow the same review process, and you can still follow up through the private access key generated at submission.
What situations should be reported here?
Any issue that may compromise the security, ethical standards or operational soundness of Garbo. This includes behaviour, practices or decisions that create risk or undermine trust in the project. It is not a channel for general inquiries, support requests or unrelated technical matters.
What type of information should not be sent?
The system must not be used to transmit classified material, unlawfully obtained data or content that breaches legal or contractual obligations. It is also not intended for sharing exploit code or sensitive technical artefacts outside a responsible disclosure context.
Who reviews the reports and how is confidentiality protected?
Only a restricted internal team handles submissions. Access is tightly controlled, submissions are encrypted and the platform is designed to maintain confidentiality—including when follow-up is needed with anonymous reporters.