Security
GICinno / Security & Responsible Technology
Security is part of trusted intelligence.
GICinno recognizes that AI, data and digital systems must be designed and operated with security, privacy, resilience and accountability in mind. This page describes our security approach, expectations for responsible use and how to report potential vulnerabilities affecting GICinno public systems.
GICinno security principle
Secure systems are not only protected systems. They are systems that can be understood, monitored and improved.
How to use this page
A public overview, not a security guarantee.
This page explains GICinno’s security-minded approach and provides a channel for reporting potential security issues. It does not disclose sensitive technical architecture, security configurations, incident response plans, certifications or control implementations.
01 / Security approach
Security is integrated into how systems are considered, designed and operated.
GICinno approaches security as a continuous practice across people, processes, data, technology, suppliers and operations. Our goal is to manage security risk in a way that is proportionate to the systems, information, users and services involved.
We use the following high-level security outcomes as a practical organizing model: governance, identification, protection, detection, response and recovery. This aligns with the six functions described in NIST Cybersecurity Framework 2.0. [35][36]
01 / Govern
Set accountability
Define security responsibilities, policies, risk ownership and decision processes.
02 / Identify
Understand assets and risk
Maintain awareness of systems, data, dependencies, threats and relevant obligations.
03 / Protect
Apply safeguards
Use appropriate access, authentication, data-protection and secure-development practices.
04 / Detect
Look for adverse events
Use reasonable monitoring, logging and review practices to identify potential issues.
05 / Respond
Contain and communicate
Investigate, manage, mitigate and communicate security incidents appropriately.
06 / Recover
Restore and improve
Restore affected operations where needed and learn from incidents to strengthen resilience.
02 / Shared responsibility
Security requires participation from everyone who uses or supports a system.
Security is not only a technical responsibility. GICinno expects employees, contractors, service providers, clients, partners and users to act responsibly when using systems, sharing information or reporting concerns.
- Use strong, unique credentials and protect authentication methods.
- Do not share passwords, access tokens or confidential information through insecure channels.
- Use approved systems and access pathways for sensitive or client information.
- Report suspected phishing, impersonation, unauthorized access or unusual behavior promptly.
- Keep devices, browsers, operating systems and applications appropriately updated.
- Use website forms, email and messaging channels only for information appropriate to those channels.
- Do not submit sensitive data through general public forms unless specifically instructed to use a secure process.
03 / Security-minded practices
Examples of practices GICinno may apply based on context and risk.
Security measures should be appropriate to the nature of the system, information, service and risk environment. Depending on context, GICinno may use a combination of organizational, technical and operational controls.
| Area | Security objective | Examples of possible practices |
|---|---|---|
| Access management | Ensure access is appropriate to the user and task. | Role-based access, least privilege, account review, authentication controls and access removal processes. |
| Data protection | Protect sensitive or confidential information appropriately. | Data classification, approved storage, controlled sharing, encryption where appropriate, retention and deletion processes. |
| Secure development | Reduce security risk in software, websites, APIs and integrations. | Code review, dependency review, testing, secrets management, environment separation and vulnerability remediation processes. |
| Operational monitoring | Detect and investigate potentially adverse events. | Logging, alerting, system review, access monitoring and incident-management procedures. |
| Third-party management | Understand security dependencies in external services. | Vendor assessment, contractual requirements, access control, service review and risk-based oversight. |
| Continuity & recovery | Support resilient operations and recovery from disruption. | Backups, restoration processes, continuity planning, incident learning and prioritized recovery activities. |
GICinno may change or improve these practices over time. We do not publish detailed defensive configurations, internal security architecture or vulnerability-management information that could increase risk to systems, clients or users.
04 / Vulnerability reporting
Report a potential security issue responsibly.
If you believe you have identified a security vulnerability affecting an in-scope GICinno public system, we encourage you to report it responsibly. Good-faith vulnerability disclosure can help organizations receive, triage, analyze and address potential security issues. CISA describes vulnerability disclosure as a way to support coordinated reporting and remediation. [32]
Security reporting channel
Send a responsible vulnerability report.
Email potential vulnerability reports to:
[SECURITY EMAIL]Use the subject line: “GICinno Security Vulnerability Report”. Do not include sensitive exploit data in an unencrypted email if a safer secure-sharing channel can be arranged. You may ask us for a secure method before sharing sensitive technical details.
What to include in a report
- A clear description of the potential vulnerability and affected system or URL.
- The date and time you discovered the issue, including relevant time zone if known.
- Steps to reproduce the issue safely and reliably.
- The potential impact you believe the issue may have.
- Relevant screenshots, request/response examples or proof-of-concept details, if safe to provide.
- Your preferred contact details so we can follow up with questions.
- Any recommended mitigation or remediation ideas, if you have them.
05 / Reporting scope
What this public reporting channel may cover
Unless we publish a more specific vulnerability-disclosure policy, this reporting channel is intended for potential vulnerabilities affecting public, internet-accessible GICinno-controlled systems, including:
- The official GICinno website and its public subdomains, where owned and operated by GICinno.
- Public website forms and public-facing integrations under GICinno’s control.
- Publicly available GICinno web applications, if specifically identified as operated by GICinno.
If you are uncertain whether a system is in scope, contact [SECURITY EMAIL] before performing any testing beyond normal browser interaction.
06 / Good-faith security research
How to report responsibly and safely
GICinno welcomes good-faith reports that are intended to improve security. We ask security researchers to act responsibly, minimize impact and avoid accessing, altering, destroying, disclosing or retaining data that does not belong to them.
When conducting research against a public GICinno system, you should:
- Use only the minimum level of testing needed to confirm a potential issue.
- Stop testing if you encounter personal data, confidential data, client data or sensitive systems.
- Do not access, download, modify, delete, encrypt or exfiltrate information.
- Do not establish persistence, pivot into other systems or attempt to gain command-line, administrator or privileged access.
- Do not perform denial-of-service, load-testing, spam, social-engineering, phishing or physical-security attacks.
- Do not target GICinno personnel, customers, suppliers, partners or third-party systems.
- Do not publicly disclose the issue until GICinno has had a reasonable opportunity to investigate and address it.
- Keep vulnerability details confidential while GICinno reviews the report, unless disclosure is required by law.
We will consider good-faith research carried out within these guidelines when assessing a report. However, this policy does not authorize activity that is unlawful, causes harm, violates third-party rights, breaches a contract, disrupts service or exceeds the scope described above.
07 / Examples of issues that may be out of scope
Report meaningful security risks, not only theoretical concerns.
The following may be considered out of scope or may not qualify as a security vulnerability unless accompanied by a demonstrated, material impact:
- Issues involving third-party products or services not controlled by GICinno.
- Social engineering, phishing, impersonation or manipulation of personnel.
- Denial-of-service or volumetric testing.
- Missing non-security HTTP headers without demonstrated impact.
- Generic scanner output without reproducible evidence of a meaningful vulnerability.
- Self-XSS or attacks that require a victim to paste code into their browser console.
- Clickjacking findings without demonstrated sensitive action or material impact.
- Rate-limit concerns without evidence of security impact or authorization to test safely.
- Reports based solely on outdated or speculative vulnerability information without evidence that the issue affects an in-scope system.
- Issues requiring physical access, compromised credentials or insider access unless expressly authorized.
GICinno may update reporting scope and out-of-scope examples as systems, services and risks evolve.
08 / Our response process
How GICinno intends to handle reports
When we receive a potential vulnerability report through the designated channel, we intend to follow a risk-based process that may include:
- Acknowledging receipt, where we can safely and reasonably do so.
- Reviewing the information to determine whether the report appears to be in scope and actionable.
- Requesting clarification or additional evidence where necessary.
- Assessing potential impact, affected systems, users and data.
- Prioritizing remediation or mitigation based on risk and operational context.
- Communicating with relevant stakeholders, service providers or authorities where appropriate.
- Reviewing lessons learned and improving controls where practical.
We do not guarantee a specific response, remediation or disclosure timeline. If GICinno publishes security acknowledgement or disclosure commitments in the future, this page will be updated with the approved timelines:
- Target acknowledgement time: [SECURITY ACKNOWLEDGEMENT TIME].
- Target status-update time: [SECURITY UPDATE TIME].
09 / AI, data and intelligent-system security
Security and trust must extend beyond the website.
GICinno recognizes that AI and data systems can introduce security and privacy considerations beyond traditional web applications. Depending on the context, this can include model inputs and outputs, prompt handling, data sources, retrieval systems, APIs, tool access, automation, model monitoring, user permissions and human oversight.
GICinno’s approach to AI and data security may include consideration of:
- Appropriate data access, classification, minimization and retention practices.
- Access control and permission boundaries for AI tools, models, agents and connected systems.
- Prompt, input, output and tool-use safeguards appropriate to the use case.
- Evaluation and monitoring for unexpected, unsafe or inappropriate system behavior.
- Human review, escalation and auditability for higher-impact workflows.
- Secure integration design across APIs, cloud services, data platforms and third-party tools.
- Privacy, explainability, resilience and governance considerations throughout the AI lifecycle.
More information about GICinno’s approach to responsible AI is available through the Responsible AI and Trustworthy AI pages.
10 / Security incidents
Responding to suspected security events
If GICinno becomes aware of a potential security incident, we may investigate, contain, assess, mitigate, recover and communicate in accordance with applicable law, contractual obligations, risk context and internal response procedures.
Where legally required, GICinno may notify affected individuals, clients, partners, service providers, regulators, insurers, authorities or other stakeholders. The nature and timing of any notification will depend on the facts, applicable requirements and risk assessment.
For privacy-related questions, please see the Privacy Policy or contact [PRIVACY EMAIL].
11 / Third-party services
Security depends on the wider technology ecosystem.
GICinno may rely on third-party platforms, infrastructure, software, hosting, analytics, email, cloud, form, communication or collaboration services. Each provider may operate under its own security, privacy, availability and service terms.
GICinno may assess, select and manage third-party services in a manner appropriate to the relevant business, technical and security context. However, we cannot guarantee the security or availability of third-party systems outside our control.
12 / Changes to this page
How security information may be updated
GICinno may update this Security page, vulnerability-reporting guidance or security contact details as our systems, services, risk environment, legal requirements and security practices evolve.
The “Last Updated” date at the top of this page will be revised when material changes are made. We encourage security researchers, clients, users and partners to review this page before submitting a report.
13 / Security contact
Contact GICinno about a security concern
For potential vulnerabilities affecting GICinno public systems, security questions or responsible-disclosure communication, contact:
- Security email: [SECURITY EMAIL]
- Privacy email: [PRIVACY EMAIL]
- General contact: [GENERAL EMAIL]
- Postal address: [REGISTERED ADDRESS]
Do not send credentials, sensitive personal data, client data, exploit payloads, malware or other harmful material through general email. If you need a secure method to share sensitive evidence, request instructions from the security contact first.
Security reporting
Help us protect the systems that support intelligent work.
If you have identified a potential security issue affecting an in-scope GICinno public system, report it responsibly through the verified security contact after this page has been completed and approved.
Report a potential vulnerability ↗