ThumbGate provides pre-action control for AI agents: allow, warn, require approval, or hard-deny tool calls based on configured rules. It is not a guarantee that every unsafe action is detected.
The default local engine keeps workspace source and local lessons on your machine. Hosted surfaces process account, billing, device pairing, and runner operational logs as described in the Privacy Policy.
For enterprise customers under a signed agreement that includes incident terms, the draft contractual target is notification within 72 hours after confirming a personal-data or confidential hosted-content breach affecting that customer.
Email security@thumbgate.ai with “Security” in the subject. Do not file public issues for active vulnerabilities. Acknowledgement target: 48 hours.