Skip to content
Geb AI
Security

Security at Geb AI

How to report a vulnerability to us, what we commit to when you do, and how we protect your data.

Report a vulnerability

If you believe you have found a security vulnerability in Geb AI, please report it privately to [email protected], with enough detail for us to reproduce it.

What we commit to

  • We acknowledge every report within 5 business days.
  • We give a substantive response within 30 days, validate the finding and confirm when it has been fixed.
  • We protect your identity and, with your permission, credit you for the finding.
  • We never restrict you from disclosing your findings to other organisations or to CERT/CIRT bodies.
  • We do not pursue legal action against researchers who act in good faith and follow this policy.

Our security contact is also published in machine-readable form, following RFC 9116: /.well-known/security.txt

This policy mirrors section 4 of our AI Code of Conduct.

Email [email protected]

How we protect your data

A summary of the safeguards described in our Data Handling Policy:

  • Encryption in transit: message content travels over TLS 1.2 or higher.
  • Encryption at rest: stored messages are encrypted at rest.
  • Least-privilege secrets: API keys and database credentials are kept in a managed secrets store under least-privilege access policies.
  • Two-factor authentication is required for every operator account.
  • Production access is restricted to authorised personnel, and every access is logged and audited.