1. Security approach
EchoGenic applies layered safeguards across identity, application access, data handling, and operations. Controls are selected to protect the confidentiality, integrity, and availability of customer information while supporting the auditability expected of trusted equine records.
2. Identity and access
- Password hashing and protected, HTTP-only session cookies.
- Role-based permissions and private-by-default horse passport records.
- Scoped, revocable sharing for professional collaboration.
- Bot and abuse protection on sensitive public endpoints.
- Administrative review workflows for trust-sensitive operations.
3. Data protection
- Encrypted network transport for application and provider connections.
- Managed infrastructure providers with access and operational safeguards.
- Controlled document upload and time-limited download access.
- Audit events for important authentication and record actions.
- Backups and recovery capabilities appropriate to the service environment.
4. Responsible use and limitations
Security is a shared responsibility. Customers should use unique passwords, protect devices, review access grants, keep organization membership current, and avoid placing unnecessary personal information in free-text fields.
No online service can guarantee absolute security. This page describes current practices at a high level and is not a warranty or certification.
5. Report a vulnerability
If you believe you found a security vulnerability, select “Security concern” on the Contact page and include enough detail for us to reproduce the issue. Do not access data that is not yours, disrupt the service, use automated high-volume testing, or publicly disclose an unresolved issue.
We will acknowledge good-faith reports, investigate them, and coordinate remediation and disclosure when appropriate.
