Trust & Security
The platform is designed for professional developers, authorized security researchers, security teams, and organizations using AI for legitimate workflows. Security, access control, responsible platform operation, and appropriate monitoring are important parts of the platform architecture.
Compliance & legal
Contact
- Security: security@wormgpt.com
- Abuse: abuse@wormgpt.com
- Support and enterprise enquiries: wormgptsupport@gmail.com
Data protection
Encryption in transit: connections use modern TLS encryption through the production infrastructure.
Encryption at rest: where supported by the underlying managed infrastructure, customer data is protected using the database and hosting provider's encryption-at-rest capabilities.
Secret management: provider API keys, application secrets, and other sensitive server-side credentials are stored using the project's secure secret-management system and are never exposed in client-side code.
Least-privilege access: access to sensitive production information is restricted according to operational requirements.
Access control & authentication
Accounts are protected by email and password authentication, with password reset by verified email link. Customer API keys are stored only as hashes; the full key is shown once at creation and can be revoked at any time.
Application data is isolated per account and enforced by row-level database security policies, not by browser state. Social sign-in and TOTP multi-factor authentication are not currently offered.
Abuse monitoring
The platform is intended for legitimate and authorized use. Reasonable security and abuse-prevention controls, including rate limiting on chat and API traffic, protect the service against activity that violates the Acceptable Use Policy.
Suspicious activity may be reviewed and accounts may be restricted or suspended where appropriate under the applicable policies. Report suspected abuse to abuse@wormgpt.com.
Payment security
Card payments are processed through Stripe using Stripe-hosted payment infrastructure. The website never stores raw customer card information. Stripe applies 3-D Secure / SCA where required by the card issuer, and every purchase produces a transaction record in your account.
Crypto payments are handled by Cryptomus using signed invoices and signature-verified callbacks. Token grants and subscription activations are applied server-side and are protected against duplicate fulfilment.
Infrastructure
The platform runs on managed hosting and a managed Postgres database. We do not publish uptime guarantees, backup or point-in-time-recovery commitments, sandboxed-execution claims, or security or compliance certifications, because those capabilities are not independently verified for this platform.
Responsible disclosure
We welcome responsible reports concerning security issues affecting the platform. Security issues can be reported to security@wormgpt.com. Please do not include secrets, private logs, or credentials in a report.
