Security

Security built around workspace authority

GentlyAI uses technical and operational controls designed to protect customer workspaces, Brand Memory and governed AI workflows.

1. Current production controls

Identity and authority

WorkOS manages production authentication. Organisation, workspace, role and entitlement authority are resolved server-side.

Data isolation

Supabase row-level security and workspace-scoped queries protect customer records. Elevated service credentials remain server-side.

Storage

Customer files use private storage controls and authorised access paths rather than public buckets.

Extension connection

The extension uses state-bound, short-lived, single-use connection codes and PKCE-based flow controls.

Billing events

Signed Stripe webhook verification is implemented for the approved billing path. Stripe Live activation remains separately controlled.

Environment control

Validation and production environments are separated. Production credentials are not intended for browser bundles.

2. Customer responsibilities

Customers must protect accounts and devices, assign appropriate workspace roles, remove users who no longer require access, follow internal information-handling policies and submit only content they are authorised to process. Customers should separately assess external AI providers used through a BYO account.

3. Extension security boundary

The GentlyAI Governance Layer uses declared Chrome permissions for local workflow state, the side panel, the GentlyAI service and supported AI pages. Its executable logic is packaged with the extension. It does not download remote executable code.

Content is sent only after the user requests governance review or variants. Destination services retain their own authentication and publishing controls.

4. AI and service providers

GentlyAI relies on specialised providers for hosting, identity, database, governance processing and related operations. Their security, availability, retention and processing locations remain subject to their services and the configuration in use. Enterprise customers may request current provider information through the due-diligence process.

5. Monitoring and incidents

GentlyAI may keep proportionate authentication, operational, security and governance-event logs for reliability, abuse prevention, investigation and incident response. Monitoring implementation continues under separate launch controls.

Confirmed incidents are investigated and escalated. Affected customers or regulators will be notified where law or an applicable agreement requires it.

6. Certifications and limitations

GentlyAI does not claim SOC 2, ISO 27001, HIPAA, PCI or penetration-test certification unless and until that status is formally obtained and documented. A provider's certification does not automatically certify GentlyAI.

No internet-connected service can guarantee absolute security. Governance and AI outputs are decision-support tools and do not guarantee legal, factual or regulatory compliance. Human review remains required.

7. Security contact

Report a suspected security issue to security@gentlyai.ai. Do not include passwords, API keys or unnecessary customer content.

Submit a security report