Customer controls
Secure HTTP-only sessions, authenticator MFA for paid checkout, one-time recovery codes, active-session revocation, hashed API keys, private-by-default workspaces, and explicit legal acceptance.
Genealogy data can expose living relatives, private evidence, and family relationships. GeneaRoute treats a clear vulnerability-reporting path as part of the product, not a hidden support chore.
Secure HTTP-only sessions, authenticator MFA for paid checkout, one-time recovery codes, active-session revocation, hashed API keys, private-by-default workspaces, and explicit legal acceptance.
Living-person privacy preflights, human-reviewed agent changes, evidence-linked claims, source-integrity checks, signed webhook bodies, and privacy-minimized optional AI processing.
No online service is risk-free. GeneaRoute documents controls accurately, monitors critical workflows, maintains tested backups, and asks researchers to report suspected failures promptly.
Email genearoute@flygonlc.com. Remove unrelated personal data, credentials, and raw genealogy records. Flygon LC will acknowledge and investigate good-faith reports as practical. GeneaRoute does not currently operate a bug bounty, and this policy is not a promise of compensation or permission to violate law or third-party terms.
Automated discovery is also published at /.well-known/security.txt. Policy effective September 1, 2026.