Security

This page describes how GPTpost protects the data you and your customers put into it. It is written to be checked, not admired: every control listed here is implemented in the product, and the limitations section says plainly what is not yet done. We would rather lose a procurement review than pass one on a claim we cannot support.

Report a suspected vulnerability to security@oraglegpt.org.


1. Our security principles

  1. Tenant isolation is the primary control. Every record carries a tenant identity and every read and write is filtered by it. A bug that leaks across tenants is treated as the most severe class of defect.
  2. Credentials are sealed, never echoed. Social tokens, AI keys, and integration secrets are encrypted before storage, are never returned by the API, and are omitted from responses rather than returned as masked placeholders that leak length or shape.
  3. Least scope, always. We request the narrowest set of social platform permissions that supports the features a customer has switched on, and we drop scopes when a feature is switched off.
  4. Fail closed. When an authorisation decision, a policy check, or a signature verification cannot be completed, the request is refused rather than allowed.
  5. Say what is not done. Section 8 lists known limitations. We do not claim certifications we do not hold.

2. Data protection

2.1 Encryption in transit

2.2 Encryption at rest

2.3 Secret hygiene


3. Identity, authentication, and access


4. Application and network security


5. Integrity and auditability


6. Operational security


7. Incident response

If we suffer a personal data breach:

  1. We contain and investigate immediately.
  2. We notify affected customers without undue delay and within 72 hours of becoming aware, with the facts known at that time, so that a customer acting as controller can meet its own GDPR Article 33 deadline.
  3. We provide the categories and approximate volume of data involved, the likely consequences, the measures taken, and a contact point.
  4. We update customers as the investigation develops rather than waiting for a final report.
  5. Where a social platform's data is involved, we notify that platform in line with its developer terms.

Breach obligations are contractual, not merely a promise: they are set out in section 9 of Data Processing Addendum.


8. Known limitations

We publish these because a security page that lists only strengths is not a security page.

  1. No third-party audit certification. We do not hold SOC 2 Type II, ISO/IEC 27001, PCI-DSS, or HIPAA attestation, and we do not claim to. If you need an audited provider today, we are not that provider yet.
  2. No contractual uptime commitment unless one is signed in an order form. See Terms of Service section 10.
  3. No full regional pinning guarantee. Primary hosting is in Germany, and so is the object storage the Company runs itself, but AI processing at a provider a customer has configured may be in the United States under Standard Contractual Clauses. We do not offer a single-region guarantee across every subsystem. See Privacy Policy section 8.
  4. No paid bug bounty. Good-faith research is protected by the safe harbour in Acceptable Use Policy section 8, but no reward is offered.
  5. A single primary database, with no high-availability cluster and no automatic failover, and point-in-time recovery that has not yet been rehearsed end to end. This is an availability and durability limit rather than a confidentiality one.

9. Reporting a vulnerability

Email security@oraglegpt.org. Please include:

Rules of engagement, which also grant you our safe harbour:

What you can expect from us: acknowledgement within 2 business days, a remediation timeline within 10 business days, and no legal action against research conducted within these rules. The full safe harbour text is in Acceptable Use Policy section 8.


10. Security questionnaires and procurement

Enterprise buyers can request our Data Processing Addendum, our subprocessor list, and answers to a security questionnaire at dpa@oraglegpt.org. We answer questionnaires factually, including the questions where the answer is "not implemented".


11. Contact

TopicAddress
Vulnerability reportssecurity@oraglegpt.org
DPA, SCCs, security questionnairesdpa@oraglegpt.org
Privacy and data subject rightsprivacy@oraglegpt.org
Legal noticeslegal@oraglegpt.org
GPT LLM ORAGLE Ltd. Liability Co.
30 N Gould St, Ste N
Sheridan, WY 82801
United States