Security Policy

Effective date: September 27, 2026

This Security Policy describes how innovativelabs.io ("innovativelabs.io," "we," "us," or "our"), operated by G5 Capital Management, Inc., protects innovativelabs.io and the apps hosted on its subdomains (together, the "Services"), and how to report a security concern. It should be read together with our Privacy Policy and Terms of Service.

Our approach

innovativelabs.io is a workshop for prototypes and experiments, but we treat the information you trust us with seriously. We collect only what each app needs, build on established infrastructure providers, and limit who and what can reach your data.

Infrastructure

The Services run on established cloud providers that maintain their own security programs and independent audits:

  • Cloudflare hosts the websites and apps and provides DNS, network protection, and defense against denial-of-service attacks.
  • Supabase provides user authentication and the database where account and app data are stored.
  • Resend sends transactional email, such as sign-in codes and notifications.

We do not run our own physical servers.

Encryption

All traffic to and from the Services is encrypted in transit using HTTPS (TLS). Data stored in our database is encrypted at rest by our infrastructure provider.

Authentication

You sign in either with Google or with a one-time code sent to your email address. You never create or use a password for innovativelabs.io, so there's no password of yours for us to store or for anyone to steal.

When you use "Sign in with Google," we request only basic sign-in permissions (openid, email, and profile). We do not request access to your Gmail, Drive, Calendar, Contacts, or any other Google data. You can revoke our access at any time at myaccount.google.com/permissions.

Sign-in sessions are managed with secure, time-limited tokens.

Access control

  • Per-app access. Each app is set as public, shared by link, or invite-only. Link and invite access can be revoked at any time.
  • Data separation. Each app's data is kept in its own separate area of the database, and database-level access rules restrict users to the data they are permitted to see.
  • Administrative access. Only a small number of authorized administrators can access the platform's admin tools. Administrator actions, such as granting or revoking access, are recorded in an audit log.
  • Least privilege. People and systems are given only the access they need to do their job.

Secrets and credentials

API keys and other credentials are stored in the encrypted secrets storage of our hosting and infrastructure providers. They are never placed in code delivered to your browser and are never stored in the database or admin tools.

Development practices

  • Development and testing use a separate database from production, so test work does not touch real user data.
  • Database changes are tested in the development environment before being applied to production.
  • Source code is kept in a private repository with access limited to authorized people.
  • As we add features that use paid services (such as text messaging, email notifications, or AI), calls to them will pass through a central gateway with usage limits and the ability to shut off a feature quickly if something goes wrong.

Monitoring and logging

We keep activity and audit logs, such as sign-ins and administrative changes, to detect misuse, investigate problems, and keep the Services running reliably. Logs are retained for a limited period.

Data minimization and deletion

We collect only the information each app needs to function. You can request deletion of your account and data at any time by emailing support@innovativelabs.io, as described in our Privacy Policy.

Incident response

If we become aware of a security incident affecting your personal information, we will investigate promptly, take steps to contain and fix it, and notify affected users and any authorities as required by applicable law. Where required, this includes notice consistent with Texas law.

Reporting a vulnerability

If you believe you have found a security vulnerability in the Services, please email support@innovativelabs.io with the subject line "Security Report." Please include:

  • A description of the issue and where you found it
  • Steps to reproduce it
  • The potential impact, if known

We ask that you give us reasonable time to investigate and fix the issue before disclosing it publicly. Please do not access, change, or delete other users' data, disrupt the Services, or use social engineering or physical attacks. We will not pursue action against anyone who reports a vulnerability in good faith and follows these guidelines.

We will acknowledge valid reports and let you know when the issue has been addressed. We do not currently offer a paid bug bounty.

Your part

You can help keep your account safe by protecting access to your email account and Google account, using multi-factor authentication on those accounts, and signing out of shared devices. innovativelabs.io will never ask for your password by email.

Limitations

No system is completely secure. We work to protect the Services and your information, but we cannot guarantee absolute security.

Changes to this policy

We may update this policy as the Services change. We will post the updated version on this page and change the effective date above.

Contact

innovativelabs.io G5 Capital Management, Inc. Email: support@innovativelabs.io