Genpio

Security Acknowledgments

Security researchers credited for reporting vulnerabilities to Genpio, how a report gets listed, and the safe harbour Genpio offers for good-faith research.

Last updated: August 24, 2026

This page credits the security researchers who have reported vulnerabilities to Genpio and worked with us while we fixed them. It is the page named by the Acknowledgments field of our security.txt, and it exists because a disclosure programme that never says thank you in public is asking researchers to work for nothing.

Credited researchers

No reports have been credited yet.

We would rather publish an empty list than a padded one. This page is not a measure of how secure the platform is โ€” it records reports we received, confirmed and fixed, and Genpio's public disclosure programme is new. The first entry will appear here once the first report has been resolved.

How a report gets listed

Send the report to [email protected]. What happens next is set out in full in our Security Policy ยง9; briefly:

  1. We acknowledge the report within 48 hours.
  2. We confirm or reject the finding and keep you updated while we remediate.
  3. Once the fix is deployed, we add you here โ€” with the name or handle you ask for, the month the report was resolved, and a one-line description of the class of issue.

Listing is at your option. Tell us if you would rather stay anonymous, or would rather we wait until a particular date, and we will. We will not publish your name without asking first, and we will not publish details that would help someone attack a customer.

What we credit

Reports that identified a real, reproducible weakness in a Genpio service and that were reported privately, before any public disclosure. That includes findings we ultimately decide not to fix, where the analysis was sound.

We do not credit automated scanner output submitted without validation, reports of missing hardening headers with no demonstrated impact, or findings against third-party services that merely happen to carry Genpio branding.

Safe harbour

As stated in our Security Policy, Genpio will not pursue legal action against researchers who act in good faith: who avoid privacy violations, service degradation and data destruction, who use only their own accounts and test data, and who give us a reasonable opportunity to fix an issue before disclosing it.