Security headers
A content security policy, frame protections, content-type protection, referrer policy, and restrictive permissions policy are configured.
Security at Gentlity
We describe controls that are implemented and separate them from deployment requirements still under review. We do not claim certifications we do not have.
Public website
A content security policy, frame protections, content-type protection, referrer policy, and restrictive permissions policy are configured.
The early-access form collects only business contact details and optional operational context, with bounded lengths and a honeypot/time check.
Any form provider endpoint and token remain server-side environment values. Browser analytics never receive form contents.
The analytics boundary is inactive unless a reviewed endpoint is configured. Events contain only event name, path, and timestamp.
Product data model
Gentlity’s current evidence model is designed around bounded reliability facts and explicit provenance. Core reliability operation does not require unrestricted raw prompt, response, or tool-payload collection.
No unsupported claims
Email hello@gentlity.com. Please provide a brief description of the issue, but avoid including sensitive exploit details, credentials, or other confidential information in your initial email. We'll coordinate an appropriate way to share additional details if needed. We do not currently operate a formal bug-bounty or vulnerability-disclosure program, or a guaranteed response SLA.