Genstic Logo
GENSTICAI-POWERED CREATIVE AGENCY
ServicesWorkAboutProcessContact
@genstic.coWhatsApp
ServicesWorkAboutProcessContact
Chat on WhatsAppInstagram @genstic.co
DESIGNED TO EMPOWERhello@genstic.com
Home/Legal/Security & Data Protection
System Architecture & Protection

Security & Data Protection

An overview of the high-level technical safeguards, zero-trust cryptographic boundaries, and data security standards protecting transactions on Genstic.

Effective Date: September 3, 2026•Last Updated: September 3, 2026•Version: 2026.1•Status: Active Policy

Contents

  • 1. Core Principles
  • 2. Transport Encryption
  • 3. Payment Security
  • 4. Cryptographic Auth
  • 5. Database RLS
  • 6. Private Invoice Storage
  • 7. Responsible Disclosure
01

Core Security Architecture Principles

Genstic enforces strict zero-trust boundaries between public client-side browser execution and server-side transaction handling. Our security model is structured around five immutable rules:

  • Absolute Secret Isolation: Server credentials, database passwords, and payment secrets never enter the client-side JavaScript bundle or DOM.
  • Timing-Safe Cryptography: All payment reconciliation and webhook verifications use constant-time equality comparisons to prevent timing attacks.
  • Strict Least-Privilege Access: Database access is governed by granular Row Level Security (RLS) preventing unauthorized enumeration or cross-tenant data access.
  • Zero Payment Card Ingestion: Sensitive payment instruments remain isolated within Razorpay's PCI-DSS Level 1 certified environment.
  • Zero Client Tracking: Our application operates without tracking cookies, third-party analytics pixels, or persistent user profiling.
02

Transport Layer Security (TLS/HTTPS)

All communications between your browser, our edge CDN, and serverless API endpoints are strictly encrypted in transit using TLS 1.3 / HTTPS with modern cipher suites. Unencrypted HTTP requests are automatically upgraded and redirected to secure HTTPS connections.

03

Payment Instrument Isolation

Direct Gateway Processing

When you make a payment on Genstic, your card details, UPI credentials, or netbanking accounts are processed inside an encrypted iframe hosted directly by Razorpay Software Private Limited. Genstic servers never receive, process, or store raw card numbers, CVVs, or UPI PINs.

04

Cryptographic Signature Verification

Every transaction and webhook notification is cryptographically authenticated on the server using HMAC SHA-256 hashing algorithms. Signatures are verified in constant time (`crypto.timingSafeEqual`) to eliminate timing side-channel attacks before orders are marked as paid.

05

Database Row Level Security (RLS)

Our PostgreSQL database is protected by comprehensive Row Level Security policies:

  • Anonymous public requests can only read active services and pricing catalog definitions.
  • Direct client-side queries against customer records, orders, payments, invoices, and webhook event tables are strictly denied by database engine policies.
  • All transactional record insertions and updates are executed exclusively by trusted server-side DAL connections.
06

Private Cloud Storage & Invoice Access

Commercial invoice PDFs are stored in private, non-public cloud storage buckets hosted by Supabase. Invoices cannot be publicly enumerated, crawled, or accessed without authorized transaction credentials or short-lived, cryptographically signed download tokens.

07

Responsible Disclosure & Vulnerability Reporting

We take security seriously and appreciate constructive reports from independent security researchers. If you discover a potential vulnerability or security flaw in our infrastructure, please report it responsibly:

Security Disclosure Contact

Email: privacy@genstic.com

Secondary: hello@genstic.com

Subject: Responsible Security Disclosure

Please include a detailed description of the vulnerability, steps to reproduce, and allow reasonable time for remediation before public disclosure.

Studio Identity

Genstic Studio

Cuttack, Odisha, India PIN 754022

Phone: +91 78559 42305

Genstic Logo
GENSTICAI-POWERED CREATIVE AGENCY

Genstic is an AI-powered creative agency and production studio creating commercial AI visuals, cinematic video, performance ad creatives, bespoke websites, and digital content for ambitious brands worldwide.

Services

  • AI Images
  • AI Videos
  • AI Ads
  • Websites
  • Content

Navigation

  • Services Directory
  • Selected Work
  • About Genstic
  • Process
  • Contact

Legal & Policies

  • Privacy Policy
  • Terms & Conditions
  • Refund & Cancellation
  • Intellectual Property
  • Disclaimer
  • Security & Protection

Direct Inquiries

hello@genstic.com+91 78559 42305@genstic.co (Profile)Message on Instagram DM
Worldwide Services
© 2026 GENSTIC. All rights reserved.•DESIGNED TO EMPOWER