security
Security
Last updated · August 2026
Security is treated as a foundational engineering discipline at GravityPullIndex, Inc. This page communicates our posture and principles rather than exposing implementation specifics, and will expand as our practices mature.
Security-minded engineering
We consider security from the architecture outward. Systems are designed to minimize exposure, and safeguards are part of how we build rather than an afterthought.
Data minimization
We aim to collect and retain only what is necessary to operate and to respond to inquiries. Reducing the data we hold reduces the risk associated with it.
Access controls
Access to systems and information is limited to what is necessary and is reviewed over time. Elevated access is granted intentionally and is not the default.
Monitoring
We monitor our systems for integrity and unusual activity to the extent appropriate for our current stage. These practices continue to evolve as we grow.
Responsible handling
We apply appropriate safeguards to protect information in transit and at rest. We do not expose proprietary implementation or security architecture details publicly.
Incident response principles
We maintain principles for identifying, assessing and responding to incidents. Our approach prioritizes limiting harm, understanding causes, and improving safeguards over time.
Responsible disclosure
We welcome responsible security reports. If you believe you have identified a security concern, we ask that you contact us responsibly and avoid public disclosure until we have had the opportunity to respond.
Security contact
Security reports can be submitted through our Contact page by selecting the appropriate inquiry type. We aim to acknowledge responsible reports in due course.
Posture and certifications
This page will expand as our security practices mature. We do not claim certifications, attestations, or compliance statuses that have not been formally obtained.
Questions about this document? Contact us.