Web application
HTTPS delivery, security headers, same-origin form handling, server-side input validation, rate limiting and reduced third-party browser exposure are part of the website baseline.
Security
LiveThis page describes the current public website controls and the security principles applied to the GIBP product programme. It does not claim certifications or production controls that have not been independently evidenced.
HTTPS delivery, security headers, same-origin form handling, server-side input validation, rate limiting and reduced third-party browser exposure are part of the website baseline.
Public sandbox and assistant interfaces are designed for synthetic or non-confidential data. Visitors are told not to submit credentials, identity documents or confidential customer data.
The target financial architecture keeps money movement behind mandates, policy, limits and deterministic state rather than giving unrestricted authority to probabilistic models.
Provider redundancy, degraded modes and recovery are product design goals. They are labelled Roadmap until verified through production tests and operational evidence.
If you believe you have identified a security vulnerability in a GIBP public system, report it to contact@theraeburngroup.com with “GIBP Security” in the subject. Do not access, modify or exfiltrate data that is not yours; do not perform denial-of-service testing; and allow reasonable time for investigation before public disclosure.
A dedicated security mailbox and formal safe-harbour policy should replace this interim contact before high-risk production services launch.