Security at Open Gambit

Protecting your data, gameplay, and credentials.

API Key Handling

We take the security of your API keys seriously. By default, API keys entered into Open Gambit are stored exclusively in your browser's Local Storage. They are never transmitted to our servers. When you play a game, the requests are sent securely via HTTPS directly from your client to the respective AI providers.

Cloud Synchronization

If you opt-in to Cloud Sync by creating an account, your data is encrypted in transit and at rest using industry-standard protocols. You remain in control and can delete your synchronized data at any time.

Responsible Disclosure

If you are a security researcher and have discovered a vulnerability in Open Gambit, we appreciate your help in disclosing it to us responsibly.

Please email us at security@opengambit.ai. We kindly ask that you give us a reasonable amount of time to respond and remediate the issue before making it public.