Trust & Privacy
Built on accountability
Civilizations have relied on accountability to build trust - a signature identified the author of a letter, a seal represented the authority behind it. Digital communications removed most of these signals, making impersonation effortless. Gemisis exists on the principle that trusted communications begin with accountability: people make better decisions when they know a real, identifiable entity stands behind an interaction.
Privacy
Share only what's needed. A passport officer confirms your identity without sharing your personal records. A card payment confirms you have the funds without exposing your bank balance. Gemisis follows the same principle - it returns only what's necessary to answer one question: does this communication match a channel the organization actually registered. Nothing more is disclosed.
Confirm without revealing. An organization can prove a communication genuinely came from it without exposing its internal verification records. Individuals on either end of a communication remain private - Gemisis can establish accountability if legally required, but doesn't disclose personal information simply because someone asks for it.
Security
What we actually do today
Communications data and organizational registration records are encrypted in transit and at rest.
Access to verification records is limited to what's operationally necessary - we don't retain more than the registry function requires.
We're building our security practices as a foundation from day one, not as an afterthought. We're actively working toward SOC 2 certification as we bring on institutional customers, and we'll share our certification status here as soon as it's official.
Responsible disclosure
Report a security issue
Found a security issue? Book a call with us. We aim to respond promptly and will work with you to confirm and fix the issue before any public disclosure.
We don't have a bug bounty program yet - as we grow, we intend to build one. For now, we'll credit anyone who responsibly reports a real issue.
- Attempt denial-of-service attacks
- Access or modify data that isn't yours
- Publicly disclose a vulnerability before we've had a reasonable chance to fix it
Built for regulated institutions
Banks, insurers, and government agencies operate under strict regulatory frameworks - data residency, privacy law (like PIPEDA in Canada or GDPR where applicable), and audit requirements are not optional for them, and they won't be optional for us as we build the infrastructure they rely on. We're designing Gemisis with those requirements in mind from day one, rather than retrofitting them after the fact.