Security
Security at Geb AI
How to report a vulnerability to us, what we commit to when you do, and how we protect your data.
Report a vulnerability
If you believe you have found a security vulnerability in Geb AI, please report it privately to [email protected], with enough detail for us to reproduce it.
What we commit to
- We acknowledge every report within 5 business days.
- We give a substantive response within 30 days, validate the finding and confirm when it has been fixed.
- We protect your identity and, with your permission, credit you for the finding.
- We never restrict you from disclosing your findings to other organisations or to CERT/CIRT bodies.
- We do not pursue legal action against researchers who act in good faith and follow this policy.
Our security contact is also published in machine-readable form, following RFC 9116: /.well-known/security.txt
This policy mirrors section 4 of our AI Code of Conduct.
Email [email protected]→How we protect your data
A summary of the safeguards described in our Data Handling Policy:
- Encryption in transit: message content travels over TLS 1.2 or higher.
- Encryption at rest: stored messages are encrypted at rest.
- Least-privilege secrets: API keys and database credentials are kept in a managed secrets store under least-privilege access policies.
- Two-factor authentication is required for every operator account.
- Production access is restricted to authorised personnel, and every access is logged and audited.