Security
How GaelOne™ protects the authorization checkpoint for AI-initiated transactions, and what it does not claim.
What GaelOne™ is designed to do
- Bind an authorization to the transaction fields it was issued for — the amount, the destination account and the reference — and to nothing wider.
- Recompute that transaction’s identity at the checkpoint from what the payment system is about to send, never from what the agent claimed earlier.
- Refuse a payment whose amount, destination account or reference changed after a person approved it, however small the change.
- Require a person to approve designated transactions before they can execute.
- Let a person stop everything at any moment, and have that stop outrank an authorization that is otherwise valid.
- Keep a record of what was proposed, what was decided, who decided it, and whether money moved.
- Keep organizations separate, so one company never sees or reaches another company’s transactions.
- Reject identity and organization values sent by a caller. Both come only from the signed-in session.
- Fail closed. When a valid current authorization is missing, unclear, or no longer valid, no payment call is made.
What we do not claim
A security page is only useful if it is honest about its limits. To be direct about ours:
- GaelOne™ has no third-party certification, attestation, or audit at this time.
- GaelOne™ has not undergone external penetration testing.
- GaelOne™ does not guarantee that every unauthorized action can be prevented.
You remain responsible for choosing which agents to connect, what they may be authorized to pay for, and who may approve a transaction.
Reporting a problem
If you find a security problem, please tell us before telling anyone else, and give us a reasonable chance to fix it. Use the contact address below.
Security capabilities described here reflect the current product implementation and may change as the platform develops.
GaelOne™ and related marks are proprietary to GaelOne™.
Questions about this page? Write to hello@gaelone.com, or use the contact form.