Security overview

ThumbGate · Last updated: 2026-08-12

This page is a product security summary for buyers. It is not a SOC 2 report, pen-test certificate, or compliance certification.

Control layer model

ThumbGate provides pre-action control for AI agents: allow, warn, require approval, or hard-deny tool calls based on configured rules. It is not a guarantee that every unsafe action is detected.

Local-first boundary

The default local engine keeps workspace source and local lessons on your machine. Hosted surfaces process account, billing, device pairing, and runner operational logs as described in the Privacy Policy.

Incident notification posture

For enterprise customers under a signed agreement that includes incident terms, the draft contractual target is notification within 72 hours after confirming a personal-data or confidential hosted-content breach affecting that customer.

Vulnerability disclosure

Email security@thumbgate.ai with “Security” in the subject. Do not file public issues for active vulnerabilities. Acknowledgement target: 48 hours.