Security policy
Last updated 24 July 2026
This page describes how we protect this website and the data it handles. It is separate from the security work we do for clients, which the FAQ covers.
Encryption
The whole site is served over HTTPS, with HSTS so browsers refuse an unencrypted connection. Data held by our providers is encrypted at rest. A content security policy limits what is allowed to run in the page, and further response headers block common classes of attack.
Access
Access to the tools that hold your data is limited to the people who need it, protected by strong, unique credentials and two-factor sign-in on every provider that supports it. Access is reviewed when roles change and removed when it is no longer needed.
Secrets
API keys and tokens stay out of the code and out of the browser. They live in the hosting platform's encrypted settings, are used only on the server, and are rotated if we have any reason to think one was exposed.
Providers and updates
Your data sits with established providers: Vercel, HubSpot, PostHog, Sentry, and Resend. Each runs its own security program and holds recognised certifications such as SOC 2. We keep our dependencies current and apply security updates promptly.
If something goes wrong
If we learn of a breach affecting your data, we will investigate, contain it, and notify affected people without undue delay, along with any regulator the law requires. We would rather over-communicate than have you find out elsewhere.
Reporting a security issue
If you find a security issue with this site or its subdomains, email security@gavai.io with enough detail to reproduce it. We acknowledge reports within 3 business days and keep you posted until it is resolved.
Good-faith research is welcome. If you make a genuine effort to follow this policy, avoid privacy violations and service disruption, do not access or change data that is not yours, and give us a reasonable chance to fix an issue before sharing it publicly, we will not pursue legal action over your research.
Out of scope: denial of service, spam, social engineering of gavAI or its providers, and issues in the providers' own platforms, which should go to their programs. We do not currently pay bounties, but we will credit you if you want.
Updates
We review this page as the site changes and update the date at the top.