Genviral

Security

Your content and accounts, protected

You trust Genviral with your content and your connected social accounts. We treat that as the responsibility it is. Here is how we keep your data safe, and where we are headed next.

Encryption everywhere

All traffic is served over TLS. Data is encrypted at rest on infrastructure operated by SOC 2-certified providers, and sensitive credentials are protected with application-level encryption.

Scoped access control

Every request runs through centralized authentication and workspace-scoped authorization. Access defaults to denied: you only ever reach data inside your own account and workspaces.

Connected accounts stay yours

Your social account connections are isolated per user and workspace. Tokens are never exposed to the browser, and one customer can never reach another customer's connected accounts.

Trusted infrastructure

We build on established providers: Supabase for database and authentication, AWS and Cloudflare for storage and delivery, Temporal Cloud for reliable background processing. We do not run our own data centers.

Continuous monitoring

Errors and anomalies are tracked across our web, API, and background-processing layers in real time, with health checks and structured logging that redact secrets and personal data.

Payments handled by experts

Billing is processed by PCI-compliant providers (Polar and Stripe). We never see or store full card numbers. Billing webhooks are cryptographically verified before they are trusted.

Compliance roadmap

Working toward SOC 2

We are actively preparing for a SOC 2 examination. That means formalizing the controls we already operate, encryption, access management, monitoring, change management, and vendor oversight, and documenting them so they can be independently verified. We will update this page as we reach each milestone.

Genviral is not yet SOC 2 certified. We are committed to being transparent about our progress rather than overstating it.

Secure development

Changes ship through peer review with automated tests, type checks, and a security-focused review checklist. Secrets are kept out of source code and validated at startup.

Least privilege

Administrative access is limited to a small, explicit set of people, and internal services authenticate to each other with dedicated secrets rather than shared user credentials.

Report a security issue

Found a vulnerability? We want to hear from you. Email our security team and we will respond promptly. We appreciate researchers who report issues responsibly and give us time to fix them before public disclosure.

Read more in our Privacy Policy and Terms of Service.