Identity and authority
WorkOS manages production authentication. Organisation, workspace, role and entitlement authority are resolved server-side.
GentlyAI uses technical and operational controls designed to protect customer workspaces, Brand Memory and governed AI workflows.
WorkOS manages production authentication. Organisation, workspace, role and entitlement authority are resolved server-side.
Supabase row-level security and workspace-scoped queries protect customer records. Elevated service credentials remain server-side.
Customer files use private storage controls and authorised access paths rather than public buckets.
The extension uses state-bound, short-lived, single-use connection codes and PKCE-based flow controls.
Signed Stripe webhook verification is implemented for the approved billing path. Stripe Live activation remains separately controlled.
Validation and production environments are separated. Production credentials are not intended for browser bundles.
Customers must protect accounts and devices, assign appropriate workspace roles, remove users who no longer require access, follow internal information-handling policies and submit only content they are authorised to process. Customers should separately assess external AI providers used through a BYO account.
The GentlyAI Governance Layer uses declared Chrome permissions for local workflow state, the side panel, the GentlyAI service and supported AI pages. Its executable logic is packaged with the extension. It does not download remote executable code.
Content is sent only after the user requests governance review or variants. Destination services retain their own authentication and publishing controls.
GentlyAI relies on specialised providers for hosting, identity, database, governance processing and related operations. Their security, availability, retention and processing locations remain subject to their services and the configuration in use. Enterprise customers may request current provider information through the due-diligence process.
GentlyAI may keep proportionate authentication, operational, security and governance-event logs for reliability, abuse prevention, investigation and incident response. Monitoring implementation continues under separate launch controls.
Confirmed incidents are investigated and escalated. Affected customers or regulators will be notified where law or an applicable agreement requires it.
GentlyAI does not claim SOC 2, ISO 27001, HIPAA, PCI or penetration-test certification unless and until that status is formally obtained and documented. A provider's certification does not automatically certify GentlyAI.
No internet-connected service can guarantee absolute security. Governance and AI outputs are decision-support tools and do not guarantee legal, factual or regulatory compliance. Human review remains required.
Report a suspected security issue to security@gentlyai.ai. Do not include passwords, API keys or unnecessary customer content.
Submit a security report