Genesis iTG
ServicesAI AgentsPortfolioPricingAboutContact
(775) 431-2155Request a free brand audit

Security & Trust

Our commitments for protecting client data, customer data, and the brands we operate.

Last reviewed: September 16, 2026

Overview

Genesis iTG builds and operates ecommerce brands on behalf of our clients. In the course of that work we process store data, customer records, and client advertising and analytics accounts. This page sets out the controls we operate, the platforms we rely on, and the commitments we make regarding the protection of that data.

We state only what we can evidence. Where a control is planned rather than in place, it is identified as such in the Security Roadmap section below.

Enquiries from client security teams should be directed to security@genesisitg.com.

Platform certifications

Genesis iTG builds on established platforms rather than operating its own infrastructure. Each platform maintains independent third-party certification:

Lovable
Application development and hosting. SOC 2 Type 2 (unqualified opinion), ISO/IEC 27001:2022 certified, AIUC-1 certified for AI agent security. Infrastructure hosted on Google Cloud Platform.
Supabase
Database, authentication, and file storage for applications we develop. SOC 2 Type 2. Encryption in transit and at rest.
Shopify
Ecommerce platform and payment processing. PCI DSS Level 1. Cardholder data is processed by Shopify and its payment processors. Genesis iTG does not store, process, or transmit payment card data at any point.
Google Workspace
Corporate email, documents, and collaboration. ISO/IEC 27001, SOC 2 and SOC 3.
Cloudflare
Authoritative DNS and network edge for all domains under our management.

We maintain current copies of our platforms’ audit reports and review them on reissue.

Email authentication

All domains we operate for a live brand enforce SPF, DKIM, and DMARC at a quarantine policy, with aggregate reporting monitored on a continuous basis.

Domain spoofing — the transmission of fraudulent email purporting to originate from a client’s brand — remains among the most prevalent attack vectors against ecommerce businesses, and it targets the customer rather than the infrastructure. Enforcement of DMARC across every operated domain is a control we apply as standard, including to our own corporate domain.

Data handling and access control

  • Least privilege. Personnel are granted access only to the systems required by their role. Access is revoked on role change and on departure.
  • Multi-factor authentication is mandatory on all accounts with access to client data, including platform accounts, source code repositories, and corporate email.
  • Client credentials. Where a client grants Genesis iTG access to their Shopify, advertising, or analytics accounts, we request a named user account at the minimum permission level necessary. We do not request or accept shared credentials. Client-granted access remains visible to, and revocable by, the client at all times.
  • Tenant separation. Each brand and client engagement is developed within a discrete project, with its own database instance and credential set. Client data is not commingled.
  • Source control and recovery. All applications we develop are maintained under version control in private repositories, ensuring that a platform-level failure does not result in loss of the codebase.

Data residency

Our platforms process data within the United States. Clients with data residency requirements arising from their own regulatory position should raise them prior to engagement, and we will confirm the applicable arrangements in writing.

Privacy

Our privacy policy sets out the personal information collected through genesisitg.com and the basis on which it is processed: Privacy Policy

Genesis iTG does not sell personal information. We do not use client data to train artificial intelligence models, and we do not use one client’s data in the course of work performed for another.

Reporting a security issue

Security issues should be reported to security@genesisitg.com.

We acknowledge credible reports within one business day. Where a security incident affects client data, we notify the affected client directly and without waiting for a scheduled reporting cycle.

Genesis iTG does not currently operate a paid vulnerability disclosure programme. We ask that researchers allow a reasonable remediation period before public disclosure.

Security roadmap

We consider a trust statement that omits known gaps to be of limited value. The following controls are planned rather than in place:

  • Independent certification. Genesis iTG does not currently hold its own SOC 2 or ISO/IEC 27001 certification and relies on the certifications held by its platform providers. Independent certification is on our roadmap as our client base grows.
  • Penetration testing. An independent penetration test of Genesis iTG properties has not yet been commissioned. This is planned.
  • Incident response documentation. A defined escalation path and a named security owner are in place. Formal documentation and testing of the incident response plan is in progress.

Organisations for which any of the above is a procurement requirement are encouraged to raise it during evaluation, and we will advise candidly on suitability.

Client security reviews

Genesis iTG responds to security questionnaires and will execute a reasonable non-disclosure agreement. We can provide compliance summaries for the platforms we operate on; full third-party audit reports are available directly from each vendor under that vendor’s own terms.

Contact security@genesisitg.com.

GenesisiTG

Full-stack ecommerce acceleration for growing brands.

885 Tahoe Blvd., Incline Village, NV 89451

(775) 431-2155hello@genesisitg.com

Services

Shopify + DTCAmazon Full-ServicePaid AdvertisingOps & Delivery

Pricing

StarterGrowthScale

Company

AboutPortfolioPricingBlogCareers

Partners

Shopify PartnersLovable Certified Partner 2026Lovable Certified Expert — Website BuilderLovable Certified Expert — App Builder
© 2009–2026 Genesis iTGPrivacy PolicyTermsSecurity