Genpio

Security Policy

Genpio's security practices include data encryption, access controls, consent-based cloning safeguards, and enterprise-grade infrastructure. Learn how we protect your data, voice, and brand assets.

Last updated: April 8, 2026

At Genpio, security is foundational to everything we build. Our AI avatar livestreaming platform processes sensitive data including facial likeness, voice samples, and business information. This Security Policy outlines the measures we take to protect your data and maintain the integrity of our Services.

1. Infrastructure Security

1.1 Cloud Architecture

Our platform is hosted on enterprise-grade cloud infrastructure with the following safeguards:

  • Multi-region deployment with automatic failover and disaster recovery
  • Isolated virtual private cloud (VPC) environments with strict network segmentation
  • DDoS mitigation and web application firewall (WAF) protection
  • Automated infrastructure provisioning with immutable deployments
  • 99.9% uptime SLA with real-time status monitoring

1.2 Network Security

  • All external traffic is encrypted using TLS 1.3
  • Internal service-to-service communication uses mutual TLS (mTLS)
  • Strict firewall rules with default-deny policies
  • Intrusion detection and prevention systems (IDS/IPS) monitoring all traffic
  • Regular network penetration testing by independent security firms

2. Data Protection

2.1 Encryption

  • <strong>In transit:</strong> All data transmitted between your device and our servers is encrypted using TLS 1.3
  • <strong>At rest:</strong> All stored data is encrypted using AES-256 encryption
  • <strong>Backups:</strong> Database backups are encrypted and stored in geographically separate locations
  • <strong>Key management:</strong> Encryption keys are managed through a dedicated key management service (KMS) with automatic rotation

2.2 AI Data Security

Given the sensitive nature of AI avatar data, we implement additional protections:

  • Facial and voice data is processed in isolated, sandboxed environments
  • AI training data is anonymized and cannot be traced back to individual users
  • Avatar generation models run in secure enclaves with restricted access
  • User-uploaded media is automatically purged from processing pipelines after avatar creation
  • No AI-generated content is used for model training without explicit user consent

2.3 Data Isolation

  • Each customer's data is logically isolated with strict tenant boundaries
  • Database-level access controls prevent cross-tenant data access
  • API authentication ensures requests are scoped to the authenticated account

3. Access Control

3.1 User Authentication

  • Secure password hashing using bcrypt with industry-standard salt rounds
  • Two-factor authentication (2FA) available for all accounts, mandatory for admin roles
  • Session management with automatic timeout and concurrent session limits
  • Account lockout after multiple failed login attempts
  • OAuth 2.0 and SSO integration for enterprise customers

3.2 Internal Access

  • Role-based access control (RBAC) with principle of least privilege
  • All employee access to production systems requires multi-factor authentication
  • Privileged access is logged and reviewed regularly
  • Employee access is revoked immediately upon termination
  • Regular access reviews conducted quarterly

4. Application Security

4.1 Secure Development

  • Secure Software Development Lifecycle (SSDLC) practices
  • Mandatory code reviews with security-focused checklists
  • Automated static analysis (SAST) and dependency vulnerability scanning in CI/CD
  • Dynamic application security testing (DAST) on staging environments
  • Regular third-party penetration testing and security audits

4.2 API Security

  • API authentication via secure tokens with expiration and refresh mechanisms
  • Rate limiting and throttling to prevent abuse
  • Input validation and sanitization on all endpoints
  • CORS policies restricting cross-origin requests
  • Comprehensive API logging and monitoring

5. Monitoring and Incident Response

5.1 Continuous Monitoring

  • 24/7 infrastructure and application monitoring with automated alerting
  • Centralized log management with anomaly detection
  • Real-time threat intelligence feeds integrated into our security stack
  • Automated vulnerability scanning of all production systems

5.2 Incident Response

We maintain a formal incident response plan that includes:

  • <strong>Detection:</strong> Automated and manual threat detection with defined escalation paths
  • <strong>Containment:</strong> Immediate isolation of affected systems to prevent spread
  • <strong>Investigation:</strong> Thorough forensic analysis to determine root cause and scope
  • <strong>Notification:</strong> Affected users are notified within 72 hours of confirmed data breaches, in compliance with applicable regulations
  • <strong>Recovery:</strong> System restoration from verified clean backups
  • <strong>Post-incident review:</strong> Lessons learned documented and preventive measures implemented

6. Business Continuity

  • Automated daily backups with point-in-time recovery capability
  • Disaster recovery plan tested and updated at least annually
  • Recovery Time Objective (RTO): 4 hours
  • Recovery Point Objective (RPO): 1 hour
  • Geographic redundancy across multiple cloud regions

7. Compliance

We are committed to meeting and exceeding industry security standards:

  • GDPR compliance for European Union data subjects
  • SOC 2 Type II audit in progress
  • OWASP Top 10 security practices implemented across all applications
  • Regular compliance assessments and gap analyses
  • Data Processing Agreements (DPAs) available for enterprise customers

8. Employee Security

  • Background checks conducted for all employees with access to customer data
  • Mandatory security awareness training upon onboarding and annually thereafter
  • Phishing simulation exercises conducted quarterly
  • Clean desk policy and secure workstation requirements
  • Confidentiality agreements signed by all employees and contractors

9. Vulnerability Disclosure

We welcome responsible disclosure of security vulnerabilities. If you discover a potential security issue, please report it to us:

  • Email: [email protected]
  • Please include a detailed description of the vulnerability, steps to reproduce, and any supporting evidence
  • We commit to acknowledging reports within 48 hours and providing regular updates on remediation progress
  • We will not take legal action against security researchers who act in good faith

10. Contact Us

For security-related questions or concerns, please contact our security team:

Email:

Website: