diff --git a/src/app/compliance-notice/page.tsx b/src/app/compliance-notice/page.tsx index b320cb75..488afe35 100644 --- a/src/app/compliance-notice/page.tsx +++ b/src/app/compliance-notice/page.tsx @@ -1,383 +1,187 @@ -import { Separator } from "@/components/ui/separator"; import { Badge } from "@/components/ui/badge"; +import { Separator } from "@/components/ui/separator"; -export const metadata = { title: "Compliance Notice" }; +export const metadata = { + title: "Compliance Notice", + description: + "Service eligibility, regulatory scope, verification, risk, and third-party disclosures for GEM Enterprise.", +}; + +const updatedAt = "July 7, 2026"; export default function ComplianceNoticePage() { return (
- {/* Header */}
-
-
- - Regulatory - -
-

- Compliance & Regulatory Notice +
+ + Compliance Information + +

+ Compliance & Service Notice

-
- Last updated: January 1, 2026 - · - Effective Date: January 1, 2026 -
-

- This Compliance and Regulatory Notice is provided for informational purposes and to fulfill - GEM Enterprise's regulatory disclosure obligations. Clients and prospective clients should - read this notice carefully before engaging with the Platform. +

+ Last updated: {updatedAt} +

+

+ This notice explains how service availability, eligibility, verification, and third-party + delivery may apply across the GEM Enterprise platform. It does not replace a signed service + agreement or professional legal advice.

- {/* Content */} -
- - {/* Regulatory Status */} +

- Regulatory Status + Platform and Regulatory Scope

-

- GEM Enterprise operates as a cybersecurity-first enterprise platform providing services - to qualified institutional and individual clients. Our regulatory position reflects the - nature of the services provided and the jurisdictions in which we operate. -

-
-

- Platform Registration:{" "} - GEM Enterprise maintains applicable registrations and authorizations as required by - the laws and regulations of the jurisdictions in which it operates. Specific registration - details, license numbers, and regulatory filings are available upon request from our - compliance team. [Regulatory registration details — placeholder for jurisdiction-specific - disclosures.] -

-

- Regulatory Oversight:{" "} - GEM Enterprise is subject to oversight by relevant regulatory authorities in its operating - jurisdictions. We maintain compliance programs designed to satisfy the requirements of - applicable financial services, data protection, and cybersecurity regulations. [Specific - regulatory authority disclosures — placeholder.] -

-

- Note: Regulatory registrations and authorizations are subject to ongoing maintenance and - may change. Clients are encouraged to verify current regulatory status directly with - applicable regulatory authorities. +

+

+ GEM Enterprise presents cybersecurity, digital-security, operational-support, and related + service interfaces. The availability and legal scope of a service depend on the service + selected, the customer's location, the contracting entity, and any third-party provider + involved.

+

+ The website does not, by itself, represent that GEM Enterprise is a bank, broker-dealer, + investment adviser, money transmitter, insurer, law firm, or government authority. Any + service requiring a license, registration, authorization, or regulated third-party provider + must be offered only after the applicable status and delivery arrangement have been verified + and disclosed for that service. +

+
+ Registration numbers, licensing details, and regulator references must not be inferred from + general platform language. Where a regulated status applies, the relevant legal entity, + jurisdiction, registration number, scope, and verification source should be provided in the + applicable service documentation. +
- + - {/* AML/KYC Policy */}

- Anti-Money Laundering (AML) and KYC Policy + Service Eligibility

-

- GEM Enterprise maintains a comprehensive Anti-Money Laundering and Know Your Customer - program in accordance with applicable laws and regulations, including applicable provisions - of the Bank Secrecy Act, Financial Action Task Force (FATF) recommendations, and equivalent - regulations in relevant jurisdictions. -

-
+

- Client Identification Program:{" "} - All clients are required to complete identity verification prior to accessing the Platform. - This includes collection and verification of identifying information, government-issued - identification documents, proof of address, and beneficial ownership information for - entity clients. Identity verification is conducted using reliable, independent source - documents, data, or information. + Public cybersecurity information and generally available security products do not require a + person to be an accredited investor unless a specific service page and governing agreement + state otherwise for a legitimate legal reason.

- Ongoing Due Diligence:{" "} - We conduct ongoing customer due diligence throughout the client relationship, including - monitoring of transactions and activities for unusual patterns, periodic review and - re-verification of client information, and enhanced due diligence for higher-risk clients - and relationships. + Certain institutional, financial-security, asset-related, property, or jurisdiction-limited + services may require identity verification, entity verification, eligibility review, + contractual onboarding, or approval by a third-party provider before activation.

- Sanctions Screening:{" "} - All clients and transactions are screened against applicable sanctions lists, including - those maintained by OFAC, the EU, the UN Security Council, and other relevant authorities. - We do not conduct business with sanctioned persons, entities, or jurisdictions. -

-

- Suspicious Activity:{" "} - GEM Enterprise maintains policies and procedures for identifying and reporting suspicious - activity to relevant authorities as required by law. Clients are prohibited from engaging - in any activity that constitutes, facilitates, or conceals money laundering, terrorist - financing, or other financial crimes. + Submission of an access request does not guarantee approval, service availability, pricing, + or acceptance in a particular jurisdiction.

- + - {/* Client Classification */}

- Client Classification + Identity, Entity, and Risk Review

-

- GEM Enterprise classifies clients in accordance with applicable regulatory frameworks to - ensure appropriate service delivery, disclosure standards, and regulatory treatment. -

-
-
-

Professional Clients / Institutional Investors

-

- Entities and individuals who meet the criteria for classification as professional clients - or institutional investors under applicable regulatory frameworks. This includes regulated - financial institutions, large corporate clients meeting prescribed financial thresholds, - government entities, and individuals who satisfy accreditation or professional investor - standards. Professional clients receive the standard level of investor protection - available under applicable law. -

-
-
-

Qualified Eligible Persons

-

- Individuals and entities who satisfy the definition of "qualified eligible person" or - equivalent designation under applicable regulations, including accredited investors - meeting financial thresholds and sophistication standards established by relevant - regulatory authorities. -

-
-

- GEM Enterprise does not provide services to retail clients as defined under applicable - financial services regulations. If your classification changes or you have questions - about your client classification, please contact our compliance team. +

+

+ GEM Enterprise may request identity, organization, beneficial-ownership, sanctions, fraud, + security, or source-of-funds information when required by the selected service, a provider, + a contract, or applicable law. The scope of review should be proportionate to the service.

-
-
- - - - {/* Investment Risk Disclaimer */} -
-

- Investment Risk Disclaimer -

-
-

- IMPORTANT RISK WARNING +

+ Verification may be performed by approved third-party providers. Their own notices, terms, + retention periods, geographic restrictions, and decisions may also apply. Sensitive identity + documents should be submitted only through an approved secure verification workflow, not an + ordinary contact form or email attachment unless specifically authorized.

-
-

- The services and information available through the GEM Enterprise Platform involve - significant risks. The value of investments and financial instruments can decrease as - well as increase, and you may not recover the full amount invested. Past performance is - not a reliable indicator of future results. -

-

- Cybersecurity services and associated threat intelligence information are provided based - on available data and analysis, which may be incomplete or subject to rapid change. - GEM Enterprise does not warrant that its security services will prevent all security - incidents or eliminate all cyber risks. -

-

- Before making any financial or operational decisions based on information obtained - through the Platform, you should conduct your own independent due diligence and, where - appropriate, seek advice from qualified legal, financial, tax, and cybersecurity - professionals. -

-

- GEM Enterprise does not provide investment advice, legal advice, or tax advice. Nothing - on the Platform should be construed as a recommendation to buy, sell, or hold any - financial instrument or to take any particular course of action. -

-
- - - {/* Jurisdictional Restrictions */} -
-

- Jurisdictional Restrictions -

-

- The Platform and services offered by GEM Enterprise are not available in all jurisdictions. - Certain regulatory, legal, and sanctions-based restrictions limit our ability to serve - clients in specific countries and regions. -

-

- The Platform is not available to persons or entities located in, organized under the laws - of, or ordinarily resident in countries or territories that are subject to comprehensive - international sanctions, including those designated by the U.S. Office of Foreign Assets - Control (OFAC), European Union restrictive measures, UN Security Council sanctions, or - equivalent regimes. Additionally, the Platform may be restricted in jurisdictions where - applicable licensing, registration, or regulatory approval has not been obtained. -

-

- It is your sole responsibility to ensure that your access to and use of the Platform complies - with all laws applicable in your jurisdiction, including any requirements to obtain local - regulatory approvals or licenses. GEM Enterprise makes no representation that the Platform - or its services are appropriate for or available to persons in all jurisdictions. Access - to the Platform from jurisdictions where its contents are illegal is prohibited. -

-
- - + - {/* Conflicts of Interest */}

- Conflicts of Interest Policy + Financial and Professional-Advice Disclaimer

-

- GEM Enterprise maintains a Conflicts of Interest Policy designed to identify, manage, and - mitigate conflicts of interest that may arise in connection with the delivery of our services. -

-
-

- We have implemented organizational and administrative arrangements to prevent conflicts - of interest from adversely affecting the interests of our clients. These arrangements - include information barriers between business units, disclosure policies for material - conflicts, and oversight by our compliance function. -

+

- Where conflicts of interest cannot be adequately managed through these arrangements, we - will disclose the nature of such conflicts to affected clients before providing relevant - services. Material conflicts of interest will be disclosed in writing and clients will - have the opportunity to make an informed decision regarding the engagement. + General platform content is informational. Unless a separate written agreement expressly + states otherwise, it is not investment, legal, tax, accounting, insurance, or regulated + financial advice and is not a recommendation to buy, sell, hold, transfer, or finance an + asset.

- Employees and representatives of GEM Enterprise are required to report potential conflicts - of interest and are subject to policies governing personal trading, outside business - activities, and the receipt of gifts and entertainment. + Users should perform independent due diligence and obtain advice from appropriately licensed + professionals before making financial, legal, property, compliance, or security decisions.

- + - {/* Reporting Obligations */}

- Reporting Obligations + Cybersecurity and Service Limitations

-

- GEM Enterprise is subject to various regulatory reporting obligations and maintains the - systems and processes necessary to fulfill these commitments. -

-
-

- Financial Crime Reporting:{" "} - We are legally required to report suspicious activity, money laundering, terrorist - financing, and other financial crimes to relevant authorities. Client confidentiality - does not protect information that must be disclosed under applicable law, and we may - be prohibited from informing clients of such disclosures (so-called "tipping off" - restrictions). -

+

- Regulatory Examinations:{" "} - GEM Enterprise is subject to examination by regulatory authorities and may be required - to produce client records, account information, and other documentation in connection - with such examinations. We cooperate fully with regulatory examinations and investigations. + No cybersecurity control eliminates all risk. Product descriptions, monitoring labels, + response targets, availability statements, and status indicators are subject to the actual + technical implementation and the applicable service agreement.

- Incident Reporting:{" "} - Material cybersecurity incidents affecting the Platform are subject to reporting to relevant - regulatory authorities and, where required, notification to affected clients, in accordance - with applicable cybersecurity incident reporting rules and data breach notification laws. + A feature labelled preview, demonstration, planned, connected, or available must not be + interpreted as a guarantee that it is operating as a continuously monitored production + service. Contracted service levels, where offered, are defined separately.

- + - {/* Data Protection Compliance */}

- Data Protection Compliance + Privacy and Third Parties

-

- GEM Enterprise is committed to compliance with applicable data protection and privacy laws, - including the General Data Protection Regulation (GDPR), the California Consumer Privacy - Act (CCPA) and California Privacy Rights Act (CPRA), and equivalent legislation in other - jurisdictions. -

-
+

- GDPR Compliance:{" "} - For clients and data subjects in the European Economic Area and United Kingdom, GEM - Enterprise processes personal data in accordance with GDPR requirements. We maintain - a lawful basis for all processing activities, implement data subject rights procedures, - conduct data protection impact assessments where required, and maintain records of - processing activities. Our Data Protection Officer can be contacted through our - compliance team. + GEM Enterprise does not sell personal information. Information may be processed or disclosed + where needed to provide requested services, operate and secure the platform, conduct approved + verification, prevent fraud, respond to lawful requests, or meet contractual and legal + obligations, as further described in the Privacy Policy.

- CCPA/CPRA Compliance:{" "} - California residents have rights under the CCPA and CPRA, including the right to know - about personal information collected, the right to delete personal information, the - right to opt out of the sale or sharing of personal information, and the right to - non-discrimination for exercising privacy rights. GEM Enterprise does not sell personal - information. To exercise your rights, please contact{" "} - - compliance@gemcybersecurityassist.com - - . -

-

- Data Retention and Deletion:{" "} - We retain personal data only for as long as necessary to fulfill the purposes for which - it was collected, including satisfaction of legal, regulatory, and contractual obligations. - Our data retention schedules are reviewed periodically to ensure compliance with applicable - requirements. + Third-party products, identity-verification services, payment systems, analytics tools, and + external links are governed by their own terms and privacy practices. Their inclusion does not + by itself establish a regulatory partnership, endorsement, or agency relationship.

- + - {/* Contact Compliance */}

- Contact the Compliance Team + Verification and Questions

-

- For compliance-related inquiries, regulatory questions, data protection requests, or to - report concerns regarding potential violations of applicable law or GEM Enterprise policy, - please contact our compliance team directly. -

-
-

GEM Enterprise Compliance Department

- - compliance@gemcybersecurityassist.com - -

- Our compliance team endeavors to respond to all inquiries within five (5) business days. - For urgent regulatory matters, please indicate the urgency in your subject line. -

-
-
- - - - {/* Footer */} -
-

- This Compliance and Regulatory Notice is provided for informational purposes only and does - not constitute legal advice. GEM Enterprise reserves the right to update this notice to - reflect changes in applicable laws, regulations, or our compliance program. The most current - version of this notice will be maintained on the Platform. Clients are encouraged to review - this notice periodically. +

+ Before relying on a licensing, registration, partnership, certification, service-level, or + geographic-availability statement, request the applicable current documentation through the + official contact channel. Material public claims should be reviewed whenever the underlying + evidence, provider, jurisdiction, or service changes.

-
+
); } diff --git a/src/app/contact/ContactForm.tsx b/src/app/contact/ContactForm.tsx index 916ad0c3..16ed4e88 100644 --- a/src/app/contact/ContactForm.tsx +++ b/src/app/contact/ContactForm.tsx @@ -4,6 +4,7 @@ import { useState } from "react"; import { useForm } from "react-hook-form"; import { zodResolver } from "@hookform/resolvers/zod"; import { z } from "zod"; +import Link from "next/link"; import { Button } from "@/components/ui/button"; import { Card, CardContent } from "@/components/ui/card"; import { CheckCircle2, AlertCircle, Loader2, Send } from "lucide-react"; @@ -11,25 +12,27 @@ import { CheckCircle2, AlertCircle, Loader2, Send } from "lucide-react"; const contactSchema = z.object({ fullName: z .string() + .trim() .min(2, "Full name must be at least 2 characters") .max(100, "Full name must be under 100 characters"), - email: z.string().email("Please enter a valid email address"), + email: z.string().trim().email("Please enter a valid email address"), organization: z .string() + .trim() .min(2, "Organization name must be at least 2 characters") .max(200, "Organization name must be under 200 characters"), - subject: z.enum( - ["general", "security-incident", "partnership", "other"], - { required_error: "Please select a subject" } - ), + subject: z.enum(["general", "security-incident", "partnership", "other"], { + required_error: "Please select a subject", + }), message: z .string() + .trim() .min(20, "Message must be at least 20 characters") .max(5000, "Message must be under 5000 characters"), + website: z.string().optional(), }); type ContactFormData = z.infer; - type FormStatus = "idle" | "loading" | "success" | "error"; const subjectOptions = [ @@ -37,11 +40,14 @@ const subjectOptions = [ { value: "security-incident", label: "Security Incident" }, { value: "partnership", label: "Partnership" }, { value: "other", label: "Other" }, -]; +] as const; + +const inputClass = + "w-full rounded-lg border border-border/60 bg-input px-4 py-2.5 text-sm transition-colors placeholder:text-muted-foreground focus:border-primary/50 focus:outline-none focus:ring-2 focus:ring-ring"; export default function ContactForm() { const [status, setStatus] = useState("idle"); - const [errorMessage, setErrorMessage] = useState(""); + const [errorMessage, setErrorMessage] = useState(""); const { register, @@ -50,6 +56,7 @@ export default function ContactForm() { formState: { errors }, } = useForm({ resolver: zodResolver(contactSchema), + defaultValues: { website: "" }, }); const onSubmit = async (data: ContactFormData) => { @@ -57,20 +64,37 @@ export default function ContactForm() { setErrorMessage(""); try { - // Simulate POST to /api/contact - await new Promise((resolve, reject) => { - setTimeout(() => { - // Stub: always resolve for now - resolve(); - }, 1500); + const subjectLabel = + subjectOptions.find((option) => option.value === data.subject)?.label ?? + "Website inquiry"; + + const response = await fetch("/api/contact", { + method: "POST", + headers: { "Content-Type": "application/json" }, + body: JSON.stringify({ + name: data.fullName, + email: data.email, + subject: `${subjectLabel} — ${data.organization}`, + message: `Organization: ${data.organization}\n\n${data.message}`, + website: data.website, + }), }); + const result = (await response.json().catch(() => null)) as + | { ok?: boolean; error?: string } + | null; + + if (!response.ok || !result?.ok) { + throw new Error(result?.error || "Message submission failed"); + } + setStatus("success"); reset(); - } catch { + } catch (error) { + console.error("[contact-form] submission failed", error); setStatus("error"); setErrorMessage( - "An error occurred while submitting your message. Please try again or contact us directly." + "We could not submit your message. Please try again or use the published support contact.", ); } }; @@ -78,19 +102,15 @@ export default function ContactForm() { if (status === "success") { return ( - -
- + +
+
-

Message Received

-

- Your message has been received. Our team will respond within 1 business day. - For urgent security incidents, please use the emergency escalation contact provided. +

Message Submitted

+

+ Your message was accepted by our contact system. Response times vary by inquiry type and service coverage.

-
@@ -102,40 +122,29 @@ export default function ContactForm() {
- {/* Full Name */}
-
- {/* Email */}
-
- {/* Organization */}
-
- {/* Subject */}
-
- {/* Message */} + +
-