Security at GME AI
Companies put their documents, their customers and their name on this platform. Here is how we treat that responsibility.
How the platform is protected
- Encryption in transit. All traffic is served over TLS.
- Workspace isolation. Documents, agents and conversations are scoped to a workspace; members see only what their role grants.
- AI output guardrails. Every model reply on the platform passes a server-side policy that blocks credentials, payment card numbers and impersonation — for every agent, whatever its configuration. Per-agent guardrails let regulated tenants restrict topics further.
- Grounded answers. Agents can be locked to answer only from a company's own documents, with sources cited, refusing rather than guessing.
- Least privilege. Integration credentials are stored per member, used only by the tools they authorise, and are never shown back — even to their owner.
Reporting a vulnerability
If you believe you have found a security issue, please email security@gme-ai.com with enough detail to reproduce it. We acknowledge reports promptly, keep you informed while we fix, and never take action against good-faith research.