STAGING
Legal

Security Standards

These standards describe the baseline security controls applied by Genesis to protect account access, guild configuration, bot runtime behavior, and billing-linked entitlements.

Effective: March 4, 2026 Scope: Public site, dashboard, API, and bot-connected workflows

Plain-language summary

  • Security controls are layered across identity, runtime monitoring, and recovery operations.
  • Users, guild operators, and platform controls each have clear responsibilities.
  • See operational trust mapping in the Trust Center.

1. Security Program Overview

Our security program uses layered administrative, technical, and procedural controls designed to reduce risk, detect anomalies quickly, and support rapid incident response.

2. Control Domains

Identity and Access Management

Multi-factor authentication support, session controls, permission boundaries, and sensitive-action verification.

Application and API Security

Input validation, authorization checks, request tracing, and controlled rollout for high-risk changes.

Data Protection

Least-privilege access patterns, transport protections, event integrity checks, and controlled retention.

Monitoring and Incident Response

Live diagnostics, alerting, incident timelines, and recovery workflows for runtime and billing paths.

Reliability and Continuity

Readiness checks, dependency health monitoring, staged deployment, and rollback capabilities.

Vendor and Third-Party Risk

Scoped integration access and contractual controls for processors supporting billing and infrastructure.

3. Incident Handling

Security and reliability incidents are triaged by severity, tracked through an incident timeline, and resolved with corrective actions. Material service incidents may be communicated via status and support channels.

4. Shared Responsibility

  • Users are responsible for account credential security and authorized guild access management.
  • Genesis is responsible for platform controls, service monitoring, and operational safeguards.
  • Third-party services operate under their own security obligations and contractual commitments.

5. Reporting Security Concerns

Report vulnerabilities or security concerns to support@genesisdashboard.app. Include reproduction details, potential impact, and affected workflow context.

Security Standards FAQ

Quick answers for control expectations and reporting paths.

How often are security controls reviewed?

Controls are continuously monitored with periodic review cycles for identity, runtime, and recovery domains.

Category: controls

Where can we monitor live operational posture?

Use Status for current conditions and Trust Center for control and policy mapping.

Category: visibility

How do we report potential vulnerabilities?

Send responsible disclosure details to support with impact and reproduction context.

Category: reporting

Validate trust posture before launch

Use security, status, and support surfaces together to make release and policy decisions with confidence.