# Security at Genviral

Genviral protects customer content and connected social accounts with TLS encryption in transit, encryption at rest on SOC 2-certified infrastructure providers, workspace-scoped access control, and continuous monitoring across web, API, and background processing. Billing runs through PCI-compliant providers Polar and Stripe. Genviral is not yet SOC 2 certified; it is actively working toward a SOC 2 examination.

## Encryption everywhere

All traffic is served over TLS. Data is encrypted at rest on infrastructure operated by SOC 2-certified providers, and sensitive credentials are protected with application-level encryption.

## Scoped access control

Every request runs through centralized authentication and workspace-scoped authorization. Access defaults to denied: you only ever reach data inside your own account and workspaces.

## Connected accounts stay yours

Your social account connections are isolated per user and workspace. Tokens are never exposed to the browser, and one customer can never reach another customer's connected accounts.

## Trusted infrastructure

We build on established providers: Supabase for database and authentication, AWS and Cloudflare for storage and delivery, Temporal Cloud for reliable background processing. We do not run our own data centers.

## Continuous monitoring

Errors and anomalies are tracked across our web, API, and background-processing layers in real time, with health checks and structured logging that redact secrets and personal data.

## Payments handled by experts

Billing is processed by PCI-compliant providers (Polar and Stripe). We never see or store full card numbers. Billing webhooks are cryptographically verified before they are trusted.

## Secure development

Changes ship through peer review with automated tests, type checks, and a security-focused review checklist. Secrets are kept out of source code and validated at startup.

## Least privilege

Administrative access is limited to a small, explicit set of people, and internal services authenticate to each other with dedicated secrets rather than shared user credentials.

## Working toward SOC 2

We are actively preparing for a SOC 2 examination. That means formalizing the controls we already operate, encryption, access management, monitoring, change management, and vendor oversight, and documenting them so they can be independently verified. We will update this page as we reach each milestone. Genviral is not yet SOC 2 certified. We are committed to being transparent about our progress rather than overstating it.

## Report a security issue

Found a vulnerability? We want to hear from you. Email our security team and we will respond promptly. We appreciate researchers who report issues responsibly and give us time to fix them before public disclosure. Contact: security@genviral.io.

## Is Genviral SOC 2 certified?

Not yet. Genviral is actively preparing for a SOC 2 examination, formalizing the encryption, access management, monitoring, change management, and vendor oversight controls it already operates so they can be independently verified.

## Where is Genviral's data stored?

Genviral runs on Supabase for database and authentication, AWS and Cloudflare for storage and delivery, and Temporal Cloud for background processing. Genviral does not operate its own data centers.

## How does Genviral handle payment data?

Billing is processed by PCI-compliant providers Polar and Stripe. Genviral never sees or stores full card numbers, and billing webhooks are cryptographically verified before they are trusted.

---

Canonical HTML: https://www.genviral.io/security
