Trust
Who operates GaelOne™, what it holds, how it is isolated, and what has not been done yet.
Who operates the service
GaelOne™ is built and operated by GaelOne™, an early-stage product under active development. There is no support tier standing between an evaluator and the people who built it: the team that writes the code is the team that answers the questions. What GaelOne™ is, and who it is for, are on About.
Reach us at hello@gaelone.com.
What GaelOne™ holds
For each proposed payment: which AI, which payment system, the payment itself, and the plain-language reason the AI gave. For each decision: what GaelOne™ answered and why. For each human decision: who made it and when.
GaelOne™ does not receive the contents of the systems your AI acts on. It checks payments; it is not a data pipeline. See Architecture for the exact path.
What is enforced today
- Identity is resolved server-side from a session. A request cannot supply its own actor or organization.
- Every permission is re-read from durable storage inside the transaction that acts on it.
- Tenant boundaries are checked on every read and every write.
- A record belonging to another organization returns not found, never not authorized.
- Session tokens are stored only as hashes. The raw token is shown once and never persisted.
- Governance evidence is append-only and protected by database triggers, not only by application code.
- What a person approved is re-read immediately before execution, inside the transaction that records the result.
- Destructive test suites refuse to run unless the connected database is clearly disposable.
What has not been done
This list is here because you would find it out during a security review anyway, and a vendor who makes you dig for it has told you something about how they will behave later.
- No third-party security certification of any kind — no SOC 2, no ISO 27001, no HIPAA attestation.
- No independent penetration test has been performed.
- No formal availability target or service level commitment.
- Single-region deployment against one PostgreSQL database. No multi-region failover.
- No customer-managed encryption keys.
- No public status page.
- No verified third-party AI-platform integrations.
- No public documentation site.
If any of these is a blocker for your organization, it is better to know before an engagement than during one.
If GaelOne™ is unavailable
The path fails closed. A payment that cannot get an answer from GaelOne™ does not proceed on the assumption that it would have been allowed. An AI that cannot reach GaelOne™ is an AI that cannot send payments through it.
Responsibility
GaelOne™ authorizes transactions. You remain responsible for choosing the use case, reviewing how your AI behaves, approving the payments that need a person, and deciding whether deployment is appropriate.
Placing an AI’s payments behind GaelOne™ does not make that AI safe, correct, or suitable for a given task. It makes the payments it may actually send explicit, limited, revocable and provable.
GaelOne™ and related marks are proprietary to GaelOne™.
Questions about this page? Write to hello@gaelone.com, or use the contact form.