Security Policy

How GentlyAI approaches platform and workspace security

This Security Policy explains the operational, technical, organizational, and infrastructure safeguards used to help protect customer workspaces, governance systems, browser extension activity, and AI-assisted communication workflows.

1. Security architecture

GentlyAI uses cloud infrastructure, authentication systems, database services, browser extension systems, logging infrastructure, and operational safeguards intended to help protect workspace integrity, governance activity, and customer data.

Security controls may include authentication safeguards, encrypted transport where supported, access restrictions, environment separation, infrastructure monitoring, logging, permission management, and operational review procedures.

GentlyAI uses administrative, organizational, and technical safeguards designed to support secure AI Brand Governance workflows. No internet-connected platform can guarantee absolute security, and customers remain responsible for internal access management, user permissions, device security, content handling, and organizational governance obligations.

2. Infrastructure providers

GentlyAI may rely on third-party infrastructure and service providers to deliver the platform. These providers may include cloud hosting services, authentication providers, database providers, payment processors, CRM systems, AI providers, browser extension ecosystems, and related operational services.

Provider TypePurpose
SupabaseAuthentication, database infrastructure, workspace storage, and operational backend services.
AWS InfrastructureCloud infrastructure, storage, backups, asset delivery, exports, and future processing systems.
StripeSubscription billing, invoice management, and payment processing.
HubSpotCustomer support, CRM, onboarding, and sales operations.
AI ProvidersGovernance analysis, classification, rewrite support, and future AI-assisted governance functionality.
Browser Extension EcosystemsDistribution and management of browser extension functionality.

Customers should review the independent security documentation and policies of third-party providers where appropriate.

3. Workspace access controls

GentlyAI workspaces may support user roles, organizational access controls, workspace administration, review permissions, and approval workflows designed to help organizations manage governance activity and operational visibility.

Customers are responsible for assigning appropriate workspace roles, removing unauthorized users, protecting credentials, and maintaining internal governance policies for AI-assisted communication.

4. Browser extension security

The GentlyAI browser extension is designed to operate only within supported AI-assisted workflows and supported browser environments. Extension permissions should be limited to the minimum access necessary to provide governance functionality.

Depending on enabled functionality, the extension may process prompts, generated outputs, selected content, governance telemetry, and workspace review actions necessary to provide governance scoring, rewrite recommendations, trust analysis, and operational reporting.

GentlyAI does not use extension access to collect unrelated browsing activity, unrelated communications, or unrelated website behavior outside supported governance workflows.

5. AI provider security considerations

Depending on integrations and customer configuration, customer content may be processed through third-party AI providers such as OpenAI, Anthropic, Google, Microsoft, or future providers used to support governance functionality.

GentlyAI does not control the independent infrastructure, retention systems, model behavior, or security controls of third-party AI providers. Customers should evaluate whether content submitted through AI workflows is appropriate for external processing under their internal policies and legal obligations.

6. Encryption and transport

GentlyAI uses encrypted transport where supported by infrastructure providers and supported environments. Additional encryption, regional hosting, customer-specific infrastructure isolation, or enterprise deployment controls may require separate enterprise agreements or future product capabilities.

7. Monitoring and logging

GentlyAI may maintain operational logs, authentication records, review history, governance telemetry, error reports, and security events necessary to support platform reliability, incident response, abuse prevention, and operational analysis.

Workspace administrators may have visibility into organizational governance activity, review workflows, and usage telemetry depending on the selected plan and workspace configuration.

8. Incident response

GentlyAI may investigate suspected unauthorized access, abuse, infrastructure failures, extension misuse, credential compromise, governance manipulation attempts, or other security incidents affecting the platform.

Where required by law or contract, GentlyAI may notify affected customers or regulators regarding confirmed incidents involving customer data or material platform disruption.

9. Security limitations

Customers should not assume that AI-generated content, governance outputs, or rewrite recommendations are automatically compliant, factually correct, legally approved, or free from risk.

GentlyAI provides governance infrastructure and review support, but final responsibility for publishing decisions remains with the customer.

10. Future security evolution

GentlyAI may evolve its infrastructure, authentication systems, extension architecture, governance telemetry systems, AI provider integrations, deployment models, and security controls as the platform develops.

Enterprise-grade controls such as dedicated infrastructure, customer-specific hosting, advanced audit capabilities, regional deployment, SSO, or enhanced governance controls may be introduced in future enterprise offerings.