Trust

Security overview

A plain language view of the controls currently used to protect BMGenie accounts, listings and media.

Effective August 27, 2026

Account access

Protected workspace routes require authentication. Backend requests verify the authenticated user and apply account scope to core listing and media operations.

Private media storage

Original and enhanced media are stored as private objects. Browser uploads and media access use application issued, time limited operations rather than a permanently public storage directory.

Upload resilience

The production uploader supports resumable transfer so interrupted files can continue during the active upload workflow. File type and allowance checks are applied before processing is accepted.

Processing boundaries

Original and enhanced files are stored separately. Processing jobs have explicit states, bounded concurrency and retry handling so work does not depend on a single long browser request.

Responsible disclosure

If you believe you found a security issue, do not access or alter other users' data. Send the details to support@bmgenie.ai so the issue can be investigated.