Current controls
- Encrypted HTTPS transport for public and authenticated services.
- Managed authentication with short-lived tokens and server-side authorization checks.
- Project-scoped data access with row-level database policies.
- Secrets stored in managed secret stores rather than shipped to browsers or apps.
- Explicit approval boundaries for consequential actions and receipts for completed actions.
- Security headers, origin controls, request limits, and structured operational logging on public Workers.
- Separate development, alpha, and production environments.
Your role
Use a protected email account, keep devices updated, review connected-app scopes, avoid pasting secrets into prompts, and report unexpected activity. Genesis will add user-facing session and connection controls as beta hardening continues.
Responsible disclosure
Email hi@genesis.build with “Security report” in the subject. Include the affected URL, reproduction steps, impact, and a safe way to contact you. Do not access other users’ data, degrade service, extort, or publicly disclose before we have a reasonable opportunity to investigate. We will acknowledge credible reports promptly.
Certifications
Genesis does not currently claim SOC 2, ISO 27001, HIPAA, PCI DSS service-provider certification, or any similar independent certification. Payment-card collection will be hosted by a PCI-compliant payment processor so full card data does not enter Genesis systems.