Trust
Security
GenClara has no SOC 2 report and no independent security audit. It encrypts your file in transit and on disk and keeps it in one Amazon Web Services region in the United States, US East (Northern Virginia), with 14 days of backups. Once a year it restores a copy and checks it against the live database. Below is how the service is built today, including the list of every company that handles your data. For each statement, our test suite names the file in the code or deploy settings that makes it true.
Download the vendor questionnaire (CSV)The same answers, one row per question, filled in by us.
Independent audits
- Do you have a SOC 2 report or another independent security certification?
- No, GenClara has no SOC 2 report, no ISO 27001 certificate, and no independent security audit of any kind. This page states the controls as they are built. For each statement, our own test suite names the file in the code or the deploy settings that makes it true, and fails when that file stops saying it.
Where your data lives
- Where is customer data stored?
- Your file and your account are stored in one Amazon Web Services (AWS) region, US East (Northern Virginia) (us-east-1), in the United States, and nowhere else. Card details go straight to Stripe and never reach our servers. Emails you send us are kept in our support mailbox at Proton.
- What does the service run on?
- The app runs as containers on AWS Fargate. Your data sits in a PostgreSQL database run by Amazon RDS (AWS's managed database service), which keeps a standby copy in a second availability zone and switches to it if the main one fails. Cloudflare sits in front of the site.
- Who runs the service?
- Digent LLC runs GenClara and holds the administrative access to its AWS account.
Encryption
- Is data encrypted in transit?
- Yes, pages are served over HTTPS (encrypted web connections), and browsers are told to use only HTTPS on this site for two years. Cloudflare can reach our load balancer only on its HTTPS port, and the deploy removes any other opening it finds. The app's connection to the database is encrypted and checks the database's certificate against Amazon's published certificate authorities.
- Is data encrypted at rest?
- Yes, the database is encrypted on disk with RDS storage encryption, using a key held in AWS Key Management Service. Its automated backups are encrypted the same way.
- How are passwords and keys stored?
- Passwords must be at least 12 characters and are stored only as scrypt hashes. Invitation links, two-factor recovery codes and calendar-feed addresses are stored only as SHA-256 hashes (one-way fingerprints); API keys are stored the same way, plus the short visible prefix shown on the API keys page. Two-factor secrets are stored encrypted.
- How are the service's own secrets handled?
- They are held in AWS Secrets Manager and handed to the app when it starts; none is built into the app image. AWS manages the database password and rotates it, and the app re-reads it after a rotation.
Backups and recovery
- How is data backed up?
- AWS takes automated backups of the database and keeps them for 14 days, so it can be restored to any point in that window. The production database has deletion protection switched on.
- Do you test restoring from backup?
- Once a year we restore a copy of the production database from its backups and compare it with production: the same tables, the same schema changes, and the same accounts, allowing up to 5% fewer for sign-ups made after the copy's point in time. The copy is deleted afterwards. The last drill passed on 27 September 2026.
Access controls
- How is one customer's data kept from another's?
- Each organization's file is separate. Every request is checked against the signed-in member's organization before anything is read or written.
- What roles can members have?
- An organization has up to 5 seats, and each member holds one role. Admin: Manages billing and members, edits, approves and certifies, exports the audit log, and downloads everything. Preparer: Edits the file and prepares packages. Cannot approve or certify. Approver: Approves the file and records certifications. Cannot edit. Read-only: Reads and exports the file and its audit log, for example an examiner or outside accountant. Changes nothing. Where two or more members exist, nobody approves their own change.
- How do people sign in?
- People sign in with an email address they have confirmed and a password. Sign-in requests are rate-limited per visitor, and the session cookie is locked to genclara.com.
- Do you support two-factor authentication?
- Yes, members can turn on codes from an authenticator app. An admin can require it for the whole organization, and then a member without it, and their API keys, are refused. After 5 wrong codes, code entry locks for 15 minutes. There is no text-message or email code.
- How do API keys work?
- A key acts as the member who made it, in that member's current role. It is shown once. Removing a member ends every session they have and revokes every key they made, at once.
- Is activity logged?
- Yes, every change to the file, every approval, certification and download, every sign-in, member, invitation and two-factor change, and every API-key call goes into the organization's audit log. Its entries are hash-chained, and the database refuses to edit or delete them (they go only when the whole organization is erased). Admins and read-only members can export it.
- Can your staff see our data?
- Digent LLC can technically reach the database through its AWS account. It opens a customer's file only to fix a problem the customer reports, to restore data from a backup, or where the law requires it.
- How is the network locked down?
- The database has no public address, so it cannot be reached from the internet; inside our private network, its port is opened to the app's servers. The app's load balancer accepts traffic only from Cloudflare.
- How do you keep software up to date?
- Every 28 days the app is rebuilt from a freshly pulled base image. Dependency security fixes are applied when the full test suite still passes with them, and nothing goes live unless the suite passes.
Subprocessors
- Amazon Web Services hosts the app, the database and the account emails, in the United States.
- Stripe takes payments, keeps payment records and emails receipts.
- Cloudflare protects the site and carries traffic in transit.
- Proton hosts the support@genclara.com mailbox that receives your emails to us.
- Do you sell data, track visitors, or train AI on customer data?
- No, we do not sell personal data, show advertising, run analytics or tracking scripts, or use your data to train AI models.
This is the same list as the privacy notice, and nobody new gets access before that list changes.
Retention and deletion
- What happens to our data when we cancel?
- When you cancel, your subscription runs to the end of the month you paid for. After that the file is read-only. Nobody can change it, and everyone in your organization can still read it and download it. We do not erase it on a timer. It stays until your organization's paying admin deletes the account.
- Can we get all of our data out?
- An admin can use Download everything on the billing page at any time, including after cancelling. It is one ZIP with all of your data as JSON and CSV, every prepared form, the evidence index, the audit log, and a README explaining each file.
- What happens when we delete the account?
- When the paying admin deletes the account, the organization's file, its members' API keys, its billing record and the admin's sign-in are erased at once, for every member. Database backups keep a copy for up to 14 days, and then it is gone. A member who is not the payer and deletes their own account only leaves; the organization and its file stay.
- How long are server logs kept?
- Server logs are kept 30 days. They hold visitors' IP addresses and browser details.
Incidents and reporting
- How do we report a security problem?
- Write to support@genclara.com. The same address is published at /.well-known/security.txt.
- What happens when something goes wrong?
- Every incident that affected customers is listed on the status page with when it started, when it ended and what we changed. If a breach affects your data, we tell you as the law requires.
- Where can we see whether the service is up?
- The status page at /status runs the service's own checks, at most a minute old: the website and the API each answer their health call on our servers, the database answers a query, and Amazon SES reports that our email account may send. A problem between Cloudflare and our servers does not show in those checks, so incidents are also listed there by hand.