Report privately
Please do not disclose suspected vulnerabilities publicly. Email hello@gattyworks.com with “GazetteIntel security report” in the subject.
Include
Describe the affected component, reproduction steps, potential impact, and any suggested mitigation. Do not access, alter, or retain data beyond what is necessary to demonstrate the issue.
Our baseline
We use scoped access, encrypted transport, input validation, rate limits, source isolation, and infrastructure-level security controls. Documents, extracted text, metadata, and model output are treated as untrusted input.
Good-faith research
We welcome careful, good-faith reports that avoid privacy violations, service disruption, social engineering, and destructive testing. We will acknowledge credible reports and coordinate remediation where appropriate.