Trust
Trust Policy
Effective date: 19 September 2026 · Venture Group AI
Trust is earned by what we publish, label, and prove — not by what we promise. These are the commitments we hold ourselves to on every page of this site and every feature of the platform.
Honesty over hype
GuardBotAI is a human-made product that uses AI. We say clearly what is live, what is in demonstration, and what is planned. Features that are not yet in production are labeled as demonstrations — never presented as active protection.
We do not claim certifications, customer results, or detection rates we cannot evidence. If we cannot prove it, we do not publish it.
How we build
The platform is engineered with tenant isolation between customer organizations, server-side verification of payments and identity, rate limiting and bot protection on public endpoints, and tamper-evident records of security decisions.
Security work follows recognized public frameworks — the OWASP guidance for LLM and agentic applications among them — and we run recurring internal security and trust reviews of our own site and systems.
What we will tell you
If something goes wrong that affects your data or your service, we will tell you promptly and plainly, and tell you what we are doing about it.
Our assistant, GuardBot (GB), answers questions from approved product documentation and links to its sources. It does not make security decisions about your systems, and it never asks for passwords, API keys, or card details.
What we expect in return
Use GuardBotAI only on systems you own or are authorized to test. Report vulnerabilities to us responsibly via the contact page — we will acknowledge and investigate genuine reports.
Where the proof lives
These commitments are checkable, not decorative. Our public security status page carries every security incident we publish, with its severity, timeline, impact, and resolution, alongside the controls that exist in the running product today and a plain list of what we do not yet claim. Inside a customer account, every security-affecting action — key creation and revocation, enforcement changes, emergency containment, sensor registration and revocation — is written to a permanent record that cannot be edited or deleted from the application.