GIBP

Security

Live

Security claims should be evidenced, not inherited from architecture diagrams.

This page describes the current public website controls and the security principles applied to the GIBP product programme. It does not claim certifications or production controls that have not been independently evidenced.

Web application

HTTPS delivery, security headers, same-origin form handling, server-side input validation, rate limiting and reduced third-party browser exposure are part of the website baseline.

Data minimisation

Public sandbox and assistant interfaces are designed for synthetic or non-confidential data. Visitors are told not to submit credentials, identity documents or confidential customer data.

Deterministic financial control

The target financial architecture keeps money movement behind mandates, policy, limits and deterministic state rather than giving unrestricted authority to probabilistic models.

Resilience

Provider redundancy, degraded modes and recovery are product design goals. They are labelled Roadmap until verified through production tests and operational evidence.

Responsible vulnerability disclosure

If you believe you have identified a security vulnerability in a GIBP public system, report it to contact@theraeburngroup.com with “GIBP Security” in the subject. Do not access, modify or exfiltrate data that is not yours; do not perform denial-of-service testing; and allow reasonable time for investigation before public disclosure.

A dedicated security mailbox and formal safe-harbour policy should replace this interim contact before high-risk production services launch.

What we do not claim

  • • No certification badge appears without a current certificate and scope.
  • • No production availability percentage is published without an observed measurement window or contractual target label.
  • • No “mission-critical” claim is used as a substitute for disaster-recovery, load, security and incident evidence.