Purpose and scope
This Security Overview summarizes the protections Pocket Genes applies around accounts, integration workflows, report-access references, community features, support requests, and platform operations.
AWS and Firebase provide infrastructure and platform controls used by Pocket Genes for authentication, communications, application operation, and workflow management.
Who this page applies to
- Pocket Genes users and invited users.
- Integrators, providers, and Trusted Organizations.
- Security researchers, external reviewers, and people reporting incidents.
Definitions
Authentication
The process used to verify a user or administrator identity before granting account access.
Authorization
Application checks that decide whether an authenticated user may access a specific record, feature, provider reference, community resource, or admin action.
Confidential access information
Report codes, provider references, URLs, access tokens, identifiers, and similar values that can connect a user to a private report-access path.
Administrative access
Privileged access used to operate, support, moderate, secure, or maintain Pocket Genes.
Authentication and sessions
Private account functionality requires authenticated identity. Pocket Genes uses managed authentication and server-side sessions for protected account and administrative surfaces. Supported sign-in methods may vary by product surface and provider configuration.
Password reset, account recovery, and session handling are designed to reduce unauthorized takeover risk. Session lifetime, reauthentication, recovery behavior, and stronger verification options are configured by the relevant authentication surface.
Authorization
Authentication does not grant universal access. Pocket Genes uses relationship-based authorization before returning account records, report references, community records, support records, organization publishing tools, or admin actions.
Administrative surfaces are scoped by role and operational need, with separation between live service operation and non-production activity.
Report-access protection
- Report links, provider references, report codes, and access tokens are treated as confidential access information.
- They are kept out of public profiles, organization content, community posts, screenshots, analytics, and logs except where narrowly needed for support or security.
- Access is scoped to the intended user, authorized caregiver, or authorized workflow.
- Expiration, revocation, and provider availability are surfaced through the relevant integration or user flow when implemented.
Encryption and infrastructure
Pocket Genes uses encrypted connections for protected network communications. Cloud providers may also provide provider-managed encryption at rest for managed databases, storage, and infrastructure services.
Device-level protection also depends on the user device, operating system, app store, and account security settings.
Administrative access
- Production access is restricted to defined operational roles.
- Administrative permissions follow role-based boundaries and are removed when responsibilities change.
- Administrative systems use strong authentication, with multi-factor controls where supported.
- Sensitive administrative actions are logged where available and access is reviewed as part of operations.
- Production user information is separated from non-production activity except for controlled, minimized cases.
Product security practices
- Product changes are reviewed before publication and handled through separated environments.
- Third-party components and sensitive configuration are managed as part of release readiness.
- Testing uses test or minimized datasets where practical.
- Authentication, authorization, data rules, API routes, and app behavior are part of release readiness.
- Security reports move through severity review, remediation, validation, and closure.
Logging, monitoring, backups, and continuity
Pocket Genes may log operational, security, authentication, support, and diagnostic events to detect errors, abuse, unusual access, and service reliability issues.
Backups and managed-provider durability help support business continuity and disaster recovery. Restoration handling includes controls for deleted or restricted records.
Vendor management
Pocket Genes assesses providers according to service purpose, information involved, security controls, contractual terms, public privacy information, and operational need. The Subprocessor List identifies public providers used for Pocket Genes components.
Incident response
Incident response includes preparation, intake, detection, severity assessment, containment, investigation, remediation, recovery, communication, and lessons learned. Privacy incidents, account compromise, organization abuse, community safety issues, accessibility support requests, and security reports use different handling paths.
Security reports can be sent through the Incident-Reporting Contact page and the published security.txt file.
Pocket Genes security commitments
- Authentication, authorization, infrastructure, and application controls are configured around private access boundaries.
- Confidential access information and private user data are treated as protected information.
- Administrative access remains limited, reviewed, and logged where available.
- Security and incident reporting paths remain available for external reports.
Shared trust model
- Account holders control their credentials, devices, report links, and report codes.
- Integrators are expected to provide only authorized, necessary information.
- Community and organization surfaces are not channels for requesting private reports or access codes.
- Security research is handled through the published vulnerability-disclosure scope.
External scope notes
- Provider portals, app stores, external websites, and user devices may be outside Pocket Genes control.
- Security details may be withheld when disclosure would increase risk.
How to make a request or report a problem
Privacy, account, deletion, accessibility, safety, trusted-organization, and security requests can be sent to support@goldencrowvs.com. Use a subject line that identifies the issue, the affected Pocket Genes account or workflow, and whether the request is urgent.
Pocket Genes may need to verify the requester before changing or disclosing account information. Verification is handled proportionally to the request, the sensitivity of the information, and the risk of giving account access or private information to the wrong person.
Effective date, version, and review history
| Item | Value |
|---|---|
| Effective date | August 14, 2026 |
| Version | 1.1 |
| Last reviewed | August 2026 |
| Material changes | Expanded Trust Center format, operator identity, data-map boundaries, request paths, and responsibility sections. |
| Previous version | July 2026 Trust Center overview copy. |