GenZOS processes valuable business requirements, source material, code, project records, and AI interactions. Software Programming Group LLC uses a risk-based security program designed to protect Provider-managed portions of the Service. Security is a shared responsibility among Provider, Customers, Authorized Users, deployment operators, repositories, AI providers, and integration vendors.
Governance and Risk Management
Provider's security approach is intended to include assigned responsibility, risk assessment, documented policies, personnel confidentiality, access review, vendor oversight, secure development practices, incident response, and improvement based on identified risk. Specific controls and evidence may vary by plan and deployment.
Identity and Access
The Service may support role-based access and administrative control over projects and collaboration. Customers are responsible for accurate user lifecycle management, strong authentication, least privilege, periodic access review, protection of recovery channels, and prompt removal of users who no longer require access.
Provider personnel access to Customer Content should be limited to authorized roles with a business need, subject to confidentiality, logging, and review appropriate to the support or operational purpose.
Data Protection
Provider uses reasonable measures designed to protect data during transmission and storage where Provider controls the relevant environment. Measures may include encryption, access controls, network safeguards, environment separation, backup, monitoring, and secure deletion procedures. The applicable security exhibit or Order Form controls for a committed technical specification.
Customers must minimize sensitive data, avoid placing secrets in prompts or source files, use supported secret-management mechanisms, apply repository protections, and choose a model and deployment suitable for the data.
Secure Development and Change Management
Provider's development practices are intended to include code review, dependency management, vulnerability identification, testing, controlled changes, and remediation based on risk. No generated or human-written software is free from defects or vulnerabilities.
GenZOS Output requires independent code review, software-composition analysis, secret scanning, security testing, privacy review, performance testing, and staged deployment. Passing an AI-generated test does not establish security or production readiness.
AI and Model Security
AI workflows may be exposed to prompt injection, data leakage, unsafe tool calls, insecure Output, model changes, malicious files, dependency confusion, or unreliable reasoning. Provider may use isolation, input controls, tool restrictions, monitoring, rate limits, safety filters, or model-provider controls, depending on the feature.
Customers should keep agents on least privilege, separate development and production, require approval for consequential actions, restrict network and repository access, review model-retention options, and verify Output before use.
Repository and Integration Security
Customers control whether to connect GitHub, Bitbucket, APIs, or other services. Customers should use scoped tokens or application installations, protect branch and release rules, review integration permissions, rotate credentials, and revoke access when no longer needed. Third-party integrations apply their own security terms and controls.
Logging, Monitoring, and Response
Provider may log authentication, administrative, project, repository, model-routing, error, performance, and security events as appropriate to the Service. Provider maintains an incident-response process designed to investigate, contain, remediate, and communicate confirmed incidents according to law and contract.
Suspected compromise should be reported promptly to security@genzos.ai. Customers remain responsible for incidents within Customer-managed infrastructure, Customer-created applications, credentials, endpoints, or integrations.
Business Continuity
Provider may use backup, redundancy, recovery, and continuity measures appropriate to the Provider-managed architecture. Availability and recovery commitments apply only where stated in a Service Level Agreement or Order Form. Customers should export important code and documentation and maintain independent backups appropriate to business risk.
Customer-Managed Deployments
In a customer-managed deployment, Customer is responsible for infrastructure hardening, identity, network security, encryption keys, patching, monitoring, backups, incident response, physical security, and third-party vendors under Customer control. Provider is responsible only for components and services expressly identified in the applicable Order Form.
Certifications and Compliance
This statement does not claim SOC 2, ISO 27001, HIPAA, PCI DSS, FedRAMP, or another audit, certification, authorization, or compliance status. A Customer should rely only on a current written report, certificate, contract, or attestation that expressly covers GenZOS and the relevant deployment.
Reporting and Contact
Security incidents and vulnerabilities: security@genzos.ai
Privacy matters: privacy@genzos.ai
Support: support@genzos.ai
Postal address: Software Programming Group LLC, 5 Independence Way, Suite 300, Princeton, New Jersey 08540, United States