Security at Gentlity

Trust starts with accurate boundaries.

We describe controls that are implemented and separate them from deployment requirements still under review. We do not claim certifications we do not have.

Public website

A deliberately small attack surface.

Security headers

A content security policy, frame protections, content-type protection, referrer policy, and restrictive permissions policy are configured.

Minimal form data

The early-access form collects only business contact details and optional operational context, with bounded lengths and a honeypot/time check.

Server-side relay

Any form provider endpoint and token remain server-side environment values. Browser analytics never receive form contents.

No analytics by default

The analytics boundary is inactive unless a reviewed endpoint is configured. Events contain only event name, path, and timestamp.

Product data model

Structural reliability evidence.

Gentlity’s current evidence model is designed around bounded reliability facts and explicit provenance. Core reliability operation does not require unrestricted raw prompt, response, or tool-payload collection.

Tenant-owned application dataExplicit organization scope
Cross-tenant visibilityGeneric not-found behavior
Evidence payloadsBounded structural contracts
Deployment decisionsRecorded, immutable facts

No unsupported claims

What we are not claiming.

  • No SOC 2 or ISO 27001 certification claim
  • No penetration-test or bug-bounty claim
  • No uptime SLA claim
  • No guarantee that early-access controls satisfy your regulatory obligations

Report a security concern

Email hello@gentlity.com. Please provide a brief description of the issue, but avoid including sensitive exploit details, credentials, or other confidential information in your initial email. We'll coordinate an appropriate way to share additional details if needed. We do not currently operate a formal bug-bounty or vulnerability-disclosure program, or a guaranteed response SLA.