Last updated 27 July 2026
This page explains how to report a security issue with this website and what you can expect from us when you do.
The site is served over an encrypted connection, the data it handles is encrypted at rest, and access to it is limited to the people who need it. We do not publish the details of our internal controls; keeping them private is part of keeping them effective.
If we learn of a breach affecting your data, we will investigate, contain it, and notify affected people without undue delay, along with any regulator the law requires.
If you find a security issue with this site or its subdomains, email security@gavai.io with enough detail to reproduce it. We acknowledge reports within 3 business days and keep you posted until it is resolved.
Good-faith research is welcome. If you make a genuine effort to follow this policy, avoid privacy violations and service disruption, do not access or change data that is not yours, and give us a reasonable chance to fix an issue before sharing it publicly, we will not pursue legal action over your research.
Out of scope: denial of service, spam, and social engineering of gavAI or its providers. We do not currently pay bounties, but we will credit you if you want.
We review this page as the site changes and update the date at the top.
We publish this policy in English. Where we offer a translation and the two versions differ, the English version governs.