01Implemented safeguards
Form input is length-limited and validated on the server, a honeypot reduces simple automated abuse, submissions use generated references, database reads are not exposed publicly, and errors do not return stored data. Hosting and D1 are provided by Cloudflare through OpenAI Sites.
02What we do not claim
We do not claim a security certification, audit, bug-bounty program, penetration-test result, encryption guarantee, data-residency location, or incident response time that has not been verified.
03Report a vulnerability
Use the Contact form, choose “Privacy request,” begin the objective field with “SECURITY REPORT,” and provide a concise, non-destructive description. Do not include secrets. Do not access, alter, or retain other people’s data; disrupt service; use social engineering; or test third-party systems.
04Future service review
Any pilot involving source credentials, connected systems, monitoring data, exports, or agent actions will require separate scoping of permissions, secrets handling, isolation, retention, logging, deletion, and human approvals before those capabilities are enabled.