Security
Your content and accounts, protected
You trust Genviral with your content and your connected social accounts. We treat that as the responsibility it is. Here is how we keep your data safe, and where we are headed next.
Encryption everywhere
All traffic is served over TLS. Data is encrypted at rest on infrastructure operated by SOC 2-certified providers, and sensitive credentials are protected with application-level encryption.
Scoped access control
Every request runs through centralized authentication and workspace-scoped authorization. Access defaults to denied: you only ever reach data inside your own account and workspaces.
Connected accounts stay yours
Your social account connections are isolated per user and workspace. Tokens are never exposed to the browser, and one customer can never reach another customer's connected accounts.
Trusted infrastructure
We build on established providers: Supabase for database and authentication, AWS and Cloudflare for storage and delivery, Temporal Cloud for reliable background processing. We do not run our own data centers.
Continuous monitoring
Errors and anomalies are tracked across our web, API, and background-processing layers in real time, with health checks and structured logging that redact secrets and personal data.
Payments handled by experts
Billing is processed by PCI-compliant providers (Polar and Stripe). We never see or store full card numbers. Billing webhooks are cryptographically verified before they are trusted.
Compliance roadmap
Working toward SOC 2
We are actively preparing for a SOC 2 examination. That means formalizing the controls we already operate, encryption, access management, monitoring, change management, and vendor oversight, and documenting them so they can be independently verified. We will update this page as we reach each milestone.
Genviral is not yet SOC 2 certified. We are committed to being transparent about our progress rather than overstating it.
Secure development
Changes ship through peer review with automated tests, type checks, and a security-focused review checklist. Secrets are kept out of source code and validated at startup.
Least privilege
Administrative access is limited to a small, explicit set of people, and internal services authenticate to each other with dedicated secrets rather than shared user credentials.
Report a security issue
Found a vulnerability? We want to hear from you. Email our security team and we will respond promptly. We appreciate researchers who report issues responsibly and give us time to fix them before public disclosure.
