GenesisFlō AI logo

Security

Our apps hold things people would not hand to a stranger: health records, private journals, prayers. If you have found a way to reach data you should not be able to reach, we want to hear about it before anyone else does.

Reporting a vulnerability

Email tech@genesisflo.com with the subject Security report.

Include what you found, the steps to reproduce it, and what an attacker could do with it. A proof of concept helps. Screenshots help.

We acknowledge every report within three working days and tell you what we plan to do about it. If a fix will take longer than a fortnight, we will say so and keep you updated rather than going quiet.

Good-faith research

We will not pursue legal action against anyone who reports a vulnerability in good faith, provided you:

  • Give us a reasonable chance to fix it before telling anyone else.
  • Do not access, modify, or keep data belonging to another person. If you reach someone else's data by accident, stop, and say so in the report.
  • Do not degrade the service for other people. No denial of service, no spam, no brute forcing live accounts.
  • Test against your own accounts and your own data.

In scope

Our published apps, this website, and the backend services they talk to.

Out of scope

Reports from automated scanners with no demonstrated impact, missing security headers with no exploit attached, social engineering of our staff or our users, physical attacks, and vulnerabilities in third-party services we do not operate. Where a third party is at fault, report it to them, and tell us so we can track it.

What we do not offer

We do not run a paid bug bounty. We will credit you by name in the fix announcement if you would like to be credited, and we will say thank you properly.