Platform Security
The Gemini Presale application is built on a modern, serverless stack and runs on Lovable Cloud infrastructure. We rely on the platform’s built-in security controls, including encrypted traffic, automatic security patches, and isolated execution environments. User sessions are managed through Lovable-managed authentication with JWT tokens and secure httpOnly cookies.
Authentication & Access
Users authenticate with email/password or Google OAuth via Lovable-managed auth. Passwords are never stored in plain text. Administrative functions are protected by role-based access control (RBAC) and verified server-side. Admin actions are logged to the compliance audit log for accountability.
Data Protection
Personal data and KYC documents are stored in the backend database with row-level security policies. Only the authenticated user or an authorized admin can access their records. Data is transmitted over TLS and stored encrypted at rest by the cloud provider.
Payment & Settlement
Presale purchases are settled exclusively in Bitcoin. Participants send BTC directly to the designated address displayed in the dashboard. Gemini Presale does not store user private keys or seed phrases. We verify each transaction on-chain via its TXID before confirming a purchase.
Compliance & Audit Trail
We maintain an immutable compliance audit log that records key events such as signup, KYC submissions, terms acceptance, purchases, confirmations, wallet updates, and role changes. This log supports internal reviews and regulatory inquiries.
Smart Contracts & Token Distribution
Token contracts and distribution mechanisms will be audited by a third-party security firm before the Token Generation Event. The audit report will be published and linked from this page once available.
Responsible Disclosure
If you discover a security vulnerability, please report it responsibly to security@geminipresale.app. Do not publicly disclose vulnerabilities until we have had a reasonable opportunity to address them. We appreciate coordinated disclosure and will acknowledge contributors when appropriate.
Shared Responsibility
Security is a shared responsibility. You are responsible for keeping your account credentials secure, using a strong password, enabling secure sign-in methods, and verifying that you are on the official Gemini Presale website before sending funds or sharing information. Never share your private keys or wallet seed phrase.