Posture
Least authority, always
Every person and every process holds the narrowest authority that lets it do its job, and holds it for the shortest time that is useful. Convenience has never been accepted as a reason to widen it.
Security & access
Security that only works while everyone behaves is not security. The commitments on this page assume the opposite — and they are stated as guarantees, not as reassurance.
When a security question is contested internally, one of these settles it. They are listed in the order we apply them.
Posture
Every person and every process holds the narrowest authority that lets it do its job, and holds it for the shortest time that is useful. Convenience has never been accepted as a reason to widen it.
Posture
Privileged actions are recorded as a matter of architecture, not policy. There is no configuration in which an administrative action goes unwritten.
Posture
Controls are designed for the day a credential is already in the wrong hands. A single stolen secret is not permitted to be sufficient for anything consequential.
Posture
We do not claim a certification we have not completed or a control we have not implemented. Where something is in progress, this page says in progress.
Gold AI is an internal Ventureship application, so member organisations never manage a second credential. Everyone else gets a full account held to the identical standard.
Route one
Gold AI is an internal Ventureship application. Member organisations authenticate once at Ventureship and arrive identified — one credential to manage, one place to revoke it, and no second password for an attacker to find.
Route two
E-mail and password with verification, single-use recovery links that expire in an hour, and session invalidation everywhere on password change. Not a reduced tier of security for not being a member.
Both routes
How you arrive has no bearing on what you may do. Identity and authority are separate systems, and neither grants the other anything implicitly.
How you prove who you are and what you are then allowed to do are two different systems. Neither grants the other anything by implication.
A privilege withdrawn is withdrawn on the next action, not at the end of a session. That costs us something on every request and we pay it deliberately.
The audit trail is append-only as a matter of architecture. There is no administrative interface that edits it, because we did not build one — not for support, not for us, not for anyone.
Entries are added. Correction is a new entry that references the old one, never an overwrite.
Every action carries the person or mandate responsible, not a service account standing in for one.
Refusals are recorded alongside actions. A limit that held is as interesting as one that did not.
Exportable in full, at any time, without a request to us.
Your record exists to serve your mandate and to answer you. It has no second purpose, and we have turned down the ones that were suggested.
These are commitments about outcomes. How each is implemented is not published — the same answer every party receives, which is the point.
The instinct to understand before acting is how a small incident becomes a long one. Our first move is always to reduce authority.
The stop is the least sophisticated part of the platform precisely so that it is the last thing capable of failing. If the clever parts are unavailable, the mandate holds position and you are told.
Limits enforced during degradation
A limit is never relaxed because something upstream is unavailable. Degradation reduces capability, never protection.
Failures that are silent
A fault either escalates to you or does not exist. There is no quiet-failure path by design.
Security pages routinely imply certifications that are aspirational. Ours does not. We build to the control expectations of the recognised frameworks, we will tell you our current audit status in writing, and we will not decorate this page with a badge we have not earned.
Security reports are acknowledged the same day and routed ahead of everything else. Good-faith reporters are credited if they wish and never pursued.
Report a vulnerabilityDue diligence
No portal, no consultant, no boilerplate returned with the questions reworded. A person who understands the control answers the question about the control.
Gold AI is operated by Ventureship. Markets carry risk; every limit is yours to set.