Back to Home
Security

Security at Geosystems AI

How the AI Visibility Intelligence Platform protects customer data across encryption, access control, infrastructure, AI processing, monitoring, and incident response.

Data Protection

Geosystems AI processes brand, competitor, and narrative intelligence on behalf of customers. That data is treated as confidential customer property at every stage.

  • Customer data is never sold, brokered, or shared between tenants.
  • Customer data is never used to train third-party foundation models.
  • Data collection is limited to what is required to produce visibility intelligence.
  • Reports and exports are scoped to the workspace that generated them.

Encryption

All data is encrypted in transit and at rest across every layer of the platform.

  • TLS 1.2+ enforced for all client, API, and webhook traffic.
  • AES-256 encryption at rest for managed Postgres and object storage.
  • Secrets and API credentials stored in an encrypted secret store, never in source control.
  • HSTS and secure cookie flags enforced on all authenticated sessions.

Access Control

Authentication and authorization run on managed identity infrastructure with least-privilege defaults.

  • Password credentials are salted and hashed; plaintext passwords are never stored.
  • Short-lived JWT session tokens with server-side revocation.
  • Role-based access control separates customer, workspace, and administrative roles.
  • Row-level security policies isolate every workspace at the database layer.
  • Internal access to customer workspaces is restricted, time-bound, and logged.

Infrastructure Security

The platform runs on Tier-1 managed cloud infrastructure with no self-operated servers to patch or expose.

  • Managed Postgres with network isolation and restricted administrative access.
  • Edge-delivered application layer with automatic TLS termination and DDoS protection.
  • Immutable, versioned deployments with instant rollback.
  • No customer data stored on developer workstations or unmanaged endpoints.

Application Security

Security controls are enforced in code and verified on every deployment.

  • HMAC signature verification on all inbound webhooks (payments, integrations, automation).
  • HTML escaping and output encoding on all user-supplied content to prevent injection.
  • Input validation on every server function and public API route.
  • Content Security Policy and hardened security headers enforced platform-wide.
  • Automated dependency scanning with prompt remediation of known vulnerabilities.

AI & Data Processing

Geosystems AI queries public generative engines to measure how brands are described, ranked, and recommended.

  • Model queries use publicly observable prompts; customer confidential data is not injected into public engines.
  • Model providers are used under enterprise/API terms that exclude training on submitted content.
  • Generated intelligence is stored inside the customer's isolated workspace only.
  • Scan pipelines are stateless between customers; no cross-tenant prompt or cache reuse.
  • Sub-processors used for AI inference are listed on the Trust Center.

Monitoring & Logging

Platform activity is continuously monitored so anomalies surface quickly.

  • Authentication events, administrative actions, and report exports are logged.
  • Application error and runtime telemetry captured with alerting on failure spikes.
  • Database and edge function performance monitored for abnormal query or access patterns.
  • Audit logs available to Enterprise customers on request.

Incident Response

We operate a documented process for detecting, containing, and communicating security incidents.

  • Triage and containment begin immediately on confirmation of a suspected incident.
  • Impacted customers are notified within 72 hours of confirming a breach affecting their data.
  • Post-incident review with root cause and corrective actions shared with affected customers.
  • Escalation path reaches the founder directly; there is no silent-failure policy.

Backups & Continuity

Customer intelligence is protected against accidental loss and infrastructure failure.

  • Automated daily backups of the production database.
  • Point-in-time recovery available on the managed database tier.
  • Backups are encrypted at rest and access-restricted.
  • Restore procedures are tested as part of platform maintenance.

Third-Party Services

We keep the vendor surface deliberately small and publish it openly.

  • Sub-processors cover database, authentication, payments, email delivery, hosting, and analytics.
  • Each vendor is selected for enterprise-grade security posture and contractual data protection.
  • The full, current sub-processor list is maintained on the Trust Center.
  • A DPA with EU Standard Contractual Clauses is available for all paid tiers.

Responsible Disclosure

We welcome reports from security researchers acting in good faith.

  • Report suspected vulnerabilities to security@geosystemsai.com.
  • We acknowledge reports within 2 business days.
  • We will not pursue legal action against researchers who follow coordinated disclosure and avoid privacy violations or service disruption.
  • Please do not test against production customer data; request a sandbox instead.

Compliance, sub-processors, and retention

Certification status (SOC 2, GDPR, CCPA, ISO 27001), the full sub-processor list, data retention schedules, and DPA requests live in the Trust Center.

Security questionnaires and vendor assessments

We respond to enterprise procurement, investor diligence, and security questionnaires within 2 business days.

security@geosystemsai.com