Effective 14 August 2026
Security
This page describes the safeguards Guildcores operates today and the limitations a customer should understand during security review. It is a factual overview, not a certification.
Guildcores Pte. Ltd. is incorporated in Singapore and has its registered office at 68 Circular Road, #02-01, Singapore 049422. Security questions and responsible disclosures can be sent to info@guildcores.com.
Security posture at a glance
Guildcores is an early stage business platform. We use layered application, infrastructure, operational, and review controls. We do not currently hold a Guildcores SOC 2 or ISO 27001 certification, and the service has not yet completed an independent penetration test. Customers should evaluate the controls below against their own risk and regulatory requirements.
Identity and access
- Guildcores users sign in through Google single sign-on. The Guildcores instance has no public email signup or public password login.
- Access is restricted to authorised accounts. Roles and per-feature permissions control which product areas a user can open or change.
- Documents and meetings inherit notebook and source visibility rules. Relationship links are shown only to users with the relevant network permission.
- Administrators can grant and revoke workspace access. Customers are responsible for removing access promptly when a person changes role or leaves.
- Production administration and connected Google credentials are limited to authorised operators.
Application accountability
The service keeps separate records for authentication events, access and change events, and AI actions.
- Authentication records cover sign-in outcomes and related request information.
- Access and change records identify the actor, action, affected record type and identifier, changed field names, time, IP address, and user agent. They do not copy the changed values into the audit record.
- Deliberate opens of sensitive single-record pages, including contacts, people, documents, meetings, contracts, and invoices, are recorded. High-volume list rendering is not recorded as hundreds of separate reads.
- AI action records distinguish proposals, human approvals, rejections, applied changes, no-op results, and failures. Approval is recorded as a new event rather than editing the proposal event.
- These records are read-only in the application and are retained for up to 400 days. Super administrators can filter and paginate the records through the administration interface and download the filtered trail as CSV.
The current audit surface does not include behavioural anomaly detection, a security information and event management system, or automatic alerts for unusual access patterns.
AI controls
AI calls run through background jobs so a web request does not wait on a model response. Features that propose task or relationship changes require a human decision before changes are applied. The service records that decision.
Depending on the selected feature, OpenAI receives prompts, files, audio, images, and relevant workspace context. OpenAI states that, by default, it does not use API input or output to train or improve its models. Provider retention still depends on the account and feature configuration, so Guildcores does not claim zero data retention.
AI output can be wrong. Customers must review output before relying on it and must not use the service for solely automated decisions that could materially affect a person.
Hosting and network protection
- Production runs on a Vultr virtual server in Tokyo, Japan.
- HTTPS protects traffic between supported browsers and the application.
- The application, PostgreSQL database, uploaded files, job processing, and server backup process run in the production environment.
- Customer deployments can use separate application instances and databases. Infrastructure may still be shared unless a signed agreement expressly provides dedicated infrastructure.
- Direct database and server administration is restricted to authorised operators.
Most customer content is not currently encrypted by Guildcores at the individual database field level. We therefore do not claim application-level encryption for ordinary records or backups, and we do not claim end-to-end encryption. Access control, network transport protection, host security, and operational restrictions are the current safeguards for that content. Field-level encryption remains a planned improvement and is not represented as a shipped control.
Backups and recovery
Production creates recurring database backups and copies uploaded files into the backup set. Server-side backup copies are retained for 14 days. A designated operator device also receives the backup directory and retains copies for up to 30 days.
These copies support operational recovery. They are not a continuously replicated disaster recovery environment, and Guildcores does not currently publish a guaranteed recovery time or recovery point objective. Customer data deleted from the active service can remain in restricted backup copies until those copies age out.
Secure development
Changes are reviewed through version control and automated checks before production release. The standard release checks include:
- the full application test suite and browser-level system tests;
- Ruby style and correctness checks;
- static application security analysis;
- dependency review through the repository's automated update and advisory tooling;
- browser verification for user interface changes;
- production health checks after deployment.
Application code does not place language model calls directly in ordinary request handling. Background jobs are designed to be repeatable and use source identifiers to reduce duplicate imports and actions.
Guildcores has not yet commissioned an independent penetration test, established a public bug bounty, or completed a formal secure development certification.
Data export, retention, and deletion
An authorised administrator can request a structured workspace export. A user can request an export of their own available account data. Export archives expire after 24 hours and can be downloaded once. A recurring process removes expired or collected archives.
Active customer workspace data is scheduled for deletion within 30 days after termination or an accepted deletion request, subject to legal holds and written contract requirements. Server backups then age out after 14 days and designated operator backups after up to 30 days. Some deletion and recovery steps are operational and are not yet fully automated end to end.
Incident response
Guildcores investigates suspected confidentiality, integrity, or availability incidents, preserves available evidence, limits continuing exposure, and restores service where practical. If an incident affects customer personal data, we will notify the affected customer without undue delay after becoming aware of a Personal Data Breach and, where feasible, within 72 hours of that awareness. Notice may precede confirmation of every fact. It will include the information reasonably available at that time and will be updated as the investigation develops.
Customers remain responsible for any notice they must give to individuals or authorities in their role as controller. Guildcores will provide reasonable assistance and will not delay a first notice merely because every detail is not yet known.
Responsible disclosure
Send a suspected vulnerability to info@guildcores.com with the affected page or feature, reproduction steps, and potential impact. Do not access another person's data, disrupt production, use automated destructive testing, or publish the issue before we have had a reasonable opportunity to investigate.
We will acknowledge a good-faith report, investigate it, and provide status updates when possible. This process does not authorise activity that would otherwise be unlawful.
Current improvement priorities
The following controls are planned or under evaluation and are not claimed as present:
- independent penetration testing and a documented remediation cycle;
- formal incident exercises and customer-facing recovery objectives;
- automated anomaly alerts over access records;
- broader automation of deletion verification;
- application-level encryption for selected sensitive fields after the search and indexing design can support it safely;
- formal security certification when customer demand and operating scale justify it.
Contact
Guildcores Pte. Ltd. 68 Circular Road, #02-01 Singapore 049422 info@guildcores.com