Security & access

Designed for the day a credential is already stolen.

Security that only works while everyone behaves is not security. The commitments on this page assume the opposite — and they are stated as guarantees, not as reassurance.

01Posture

Four stances that decide every argument.

When a security question is contested internally, one of these settles it. They are listed in the order we apply them.

Posture

Least authority, always

Every person and every process holds the narrowest authority that lets it do its job, and holds it for the shortest time that is useful. Convenience has never been accepted as a reason to widen it.

Posture

Nothing silent

Privileged actions are recorded as a matter of architecture, not policy. There is no configuration in which an administrative action goes unwritten.

Posture

Assume compromise

Controls are designed for the day a credential is already in the wrong hands. A single stolen secret is not permitted to be sufficient for anything consequential.

Posture

Honest about status

We do not claim a certification we have not completed or a control we have not implemented. Where something is in progress, this page says in progress.

02Identity

Two ways in. Neither is the weaker one.

Gold AI is an internal Ventureship application, so member organisations never manage a second credential. Everyone else gets a full account held to the identical standard.

Route one

Ventureship single sign-on

Gold AI is an internal Ventureship application. Member organisations authenticate once at Ventureship and arrive identified — one credential to manage, one place to revoke it, and no second password for an attacker to find.

Route two

Direct account

E-mail and password with verification, single-use recovery links that expire in an hour, and session invalidation everywhere on password change. Not a reduced tier of security for not being a member.

Both routes

One standard

How you arrive has no bearing on what you may do. Identity and authority are separate systems, and neither grants the other anything implicitly.

How you prove who you are and what you are then allowed to do are two different systems. Neither grants the other anything by implication.

03Authority

Resolved per request, never cached for convenience.

A privilege withdrawn is withdrawn on the next action, not at the end of a session. That costs us something on every request and we pay it deliberately.

01Session establishedValidated against the identity service on every request, never trusted from a cookie alone.
02Authority resolvedRole and status re-read per request; a revoked privilege takes effect on the next action.
03Action attemptedChecked against your limits before anything else is considered.
04Action recordedWritten with actor, target and reason. The entry cannot be edited afterwards.
05Privilege withdrawnEffective immediately, with the withdrawal itself on the record.
04Your record

History grows. It is never quietly revised.

The audit trail is append-only as a matter of architecture. There is no administrative interface that edits it, because we did not build one — not for support, not for us, not for anyone.

  • Append-only

    Entries are added. Correction is a new entry that references the old one, never an overwrite.

  • Attributable

    Every action carries the person or mandate responsible, not a service account standing in for one.

  • Complete

    Refusals are recorded alongside actions. A limit that held is as interesting as one that did not.

  • Yours

    Exportable in full, at any time, without a request to us.

AU79
05Data

Collected narrowly. Used for exactly one thing.

Your record exists to serve your mandate and to answer you. It has no second purpose, and we have turned down the ones that were suggested.

  1. 01

    Collected narrowly

    What is needed to hold your mandate and answer you. Nothing gathered speculatively for a later idea.

  2. 02

    Used for one purpose

    Your data serves your mandate. It is not sold, not brokered, and not used to train anything for anyone else.

  3. 03

    Portable on demand

    Export the full record whenever you want it, without a request to us and without a fee.

  4. 04

    Deleted on request

    We retain only what law obliges us to retain, and we will tell you exactly what that is.

06Controls

What is guaranteed, stated without adjectives.

These are commitments about outcomes. How each is implemented is not published — the same answer every party receives, which is the point.

In transit & at rest
Encryption

Industry-standard cryptography throughout; no cleartext path for credentials.

Append-only
Audit integrity

Entries are added. There is no interface, for anyone, that rewrites history.

Per request
Authority checks

Re-evaluated continuously rather than cached for a session.

Multi-region
Continuity posture

No single location is permitted to be decisive.

07Response

Contain first. Investigate second.

The instinct to understand before acting is how a small incident becomes a long one. Our first move is always to reduce authority.

  1. 01

    Detect

    Anomalies in access and authority are surfaced automatically, not discovered during a review.

  2. 02

    Contain

    The first action is always to reduce authority, not to investigate at leisure.

  3. 03

    Tell you

    Affected clients hear from us with what we know, including while we still know little.

  4. 04

    Account for it

    A written account of cause, change and timing — whether or not anyone was harmed.

08Continuity

Your limits hold even when we are having a bad day.

The stop is the least sophisticated part of the platform precisely so that it is the last thing capable of failing. If the clever parts are unavailable, the mandate holds position and you are told.

Limits enforced during degradation

A limit is never relaxed because something upstream is unavailable. Degradation reduces capability, never protection.

Failures that are silent

A fault either escalates to you or does not exist. There is no quiet-failure path by design.

09Disclosure

We will not claim a certificate we do not hold.

Security pages routinely imply certifications that are aspirational. Ours does not. We build to the control expectations of the recognised frameworks, we will tell you our current audit status in writing, and we will not decorate this page with a badge we have not earned.

What we will put in writing

  • Current audit and certification status, as it actually stands
  • The control expectations we build to, framework by framework
  • Our incident history and what changed after each one
  • Exactly what data we hold about you and what law obliges us to keep

What we will not publish

  • Implementation detail of any control
  • Architecture, topology or vendor composition
  • Anything that narrows an attacker's search
  • Client identities, in any context, ever

Found something? Tell us today.

Security reports are acknowledged the same day and routed ahead of everything else. Good-faith reporters are credited if they wish and never pursued.

Report a vulnerability
10Questions

The ones your security team will ask first.

We build to the control expectations those frameworks describe — least authority, append-only audit, change attribution, encryption in transit and at rest, documented incident response. We will not tell you we hold a certificate we have not been issued. Ask us directly for current audit status and you will get a straight answer in writing.

Access to client data is scoped, logged and limited to what an operational task requires. Any such access appears in the record. There is no unlogged administrative view.

Change your password and every other session is invalidated immediately. If your organisation uses Ventureship single sign-on, revoking there removes access here at the same moment. Your mandate's limits remain in force throughout.

Yes, and organisations can require it for everybody rather than leaving it to individual choice. Where you sign in through Ventureship, your organisation's own requirements apply and are not weakened here.

No. Your record serves your mandate. It is not sold, not brokered, and not used to train anything on anyone else's behalf.

We will tell you what they guarantee, in exhaustive detail, and submit to your questions about it. We will not publish implementation detail — the same answer we give anyone who asks, which is what makes it worth something.

Due diligence

Send us your questionnaire. We answer it ourselves.

No portal, no consultant, no boilerplate returned with the questions reworded. A person who understands the control answers the question about the control.

Gold AI is operated by Ventureship. Markets carry risk; every limit is yours to set.