Security & Responsible AI Engineering | PlanckCyber

Security

Security and control are system requirements.

PlanckCyber designs AI systems around the data, permissions, actions and consequences of the actual workflow. Controls should be proportionate to risk and testable in operation.

Least privilege

Agents and applications receive only the access needed for defined tasks.

Human authority

High-impact or uncertain actions can require explicit human approval or escalation.

Data boundaries

Sensitive data handling, retention and provider exposure are reviewed as architecture decisions.

Evaluation

Model and retrieval behavior are tested against representative cases and known failure modes.

Observability

Important actions, exceptions and changes should be visible enough to investigate and improve.

Change control

Prompt, model, retrieval and workflow changes are evaluated before uncontrolled production release.

Web security baseline.

  • Server-side validation for project inquiries
  • Cloudflare Turnstile validation on the server
  • No production secrets in browser JavaScript
  • Security headers and restrictive content policy
  • No raw user HTML rendering
  • Minimal logging of inquiry content

Responsible disclosure.

The published security.txt points to this page for the current disclosure instructions. Do not send vulnerability details, exploit material, credentials or other security-sensitive information through the general project form.

PlanckCyber has not yet published a verified dedicated vulnerability-submission mailbox on this website. A dedicated contact must be confirmed before production release.

Start with the problem

Have a problem AI might solve?

You do not need a specification. Tell us what you are trying to improve.