Security

Security Policy

Information Security & Responsible Disclosure — GENURES Technologies OÜ

Last reviewed: August 2026

Security Contact

To report a security vulnerability or concern, please contact our security team directly:

[email protected]

We aim to acknowledge all security reports within 2 business days.

Responsible Disclosure Policy

GENURES Technologies OÜ welcomes responsible disclosure of security vulnerabilities. If you discover a potential security issue affecting our systems or website, we ask that you:

  • Report the vulnerability to [email protected] promptly
  • Provide sufficient detail to allow us to reproduce and assess the issue
  • Allow us reasonable time to investigate and remediate before public disclosure
  • Not exploit the vulnerability beyond what is necessary to demonstrate the issue
  • Not access, modify or delete data belonging to other users
  • Not perform denial-of-service attacks or disrupt our services

We will not pursue legal action against researchers who act in good faith and follow this responsible disclosure policy.

Data Encryption

  • All data transmitted to and from this website is encrypted using TLS (Transport Layer Security)
  • HTTPS is enforced across all pages and endpoints
  • HTTP Strict Transport Security (HSTS) is implemented
  • Sensitive data is not transmitted in URL parameters

Access Controls

  • Access to internal systems is restricted on a need-to-know basis
  • Administrative access requires multi-factor authentication
  • Access rights are reviewed periodically and revoked upon role change or departure
  • Privileged access is logged and monitored

Website Security Measures

  • HTTP security headers: Content-Security-Policy, HSTS, X-Content-Type-Options, Referrer-Policy, Permissions-Policy
  • Rate limiting on all public-facing endpoints
  • Input validation and sanitisation on all form submissions
  • Request size limits to prevent abuse
  • Server-side validation of all user-submitted data
  • No sensitive information exposed in error messages
  • Contact form does not accept file attachments

Security Monitoring

  • Security events and access logs are monitored
  • Anomalous activity triggers internal review
  • Dependencies are reviewed for known vulnerabilities
  • Security patches are applied in a timely manner

Incident Response

GENURES Technologies OÜ maintains an internal incident-response procedure. In the event of a security incident affecting personal data, we will notify affected parties and the relevant supervisory authority in accordance with our obligations under the GDPR and applicable law.

Data Retention

Personal data collected through this website is retained only for as long as necessary for the purposes for which it was collected or as required by applicable law. Privacy Policy.

Security Certifications

GENURES Technologies OÜ does not currently hold ISO 27001, SOC 2, PCI DSS or other formal security certifications. We are committed to implementing security best practices and will update this page if formal certifications are obtained.

Vendor Security

Third-party service providers with access to GENURES systems or data are required to maintain appropriate security standards and are bound by data-processing agreements. Vendor security practices are reviewed as part of our supplier-management process.