Back to Home
Trust & Security

Built for the brands AI is already talking about.

Geosystems AI handles intelligence on brands, competitors, and executive narratives. We treat that data with the controls enterprise procurement expects, and we publish exactly where we stand.

Looking for full technical detail? See our Security page.

Compliance & Certifications

Current status of certifications and frameworks we operate against.

SOC 2 Type II

In Progress

Readiness assessment underway with an independent auditor. Type II report targeted for 2026.

GDPR

Live

EU/UK data subject rights honored. DPA available on request for all paid tiers.

CCPA

Live

California consumer rights supported. Data access and deletion requests processed within 30 days.

ISO 27001

Planned

Control mapping in progress against ISO 27001:2022 Annex A.

HIPAA

Planned

Available on request for qualifying Enterprise GEO Operating System subscriptions.

SOC 2 Type II readiness reports and compliance attestations are available to active and prospective Enterprise customers under NDA. Contact security@geosystemsai.com.

Data Handling & Application Security

The controls protecting client intelligence inside the workspace.

Encryption in transit & at rest

All client data encrypted in transit via TLS 1.2+ and at rest with AES-256 across our managed Postgres and storage layers.

Authentication & access control

Workspace authentication runs on managed identity infrastructure with hashed credentials, JWT session tokens, and role-based access.

Row-level isolation

Every workspace is isolated by row-level security policies in our database. No client can read or query another tenant's intelligence.

Hardened infrastructure

Hosted on Tier-1 cloud infrastructure with managed Postgres, automated daily backups, and point-in-time recovery.

Audit logging

Administrative actions, authentication events, and report exports are logged. Audit logs available to Enterprise tier on request.

Application security

Webhook signature verification (HMAC), HTML escaping on all user-supplied content, and CSP headers enforced across the platform.

Our Operating Principles

Your data is yours.

We never sell client data, never train third-party models on it, and never share it across tenants.

Least-privilege by default.

Internal access to client workspaces is restricted, logged, and granted only when explicitly required for delivery.

Disclosure over silence.

Security incidents affecting client data are disclosed to impacted customers within 72 hours of confirmation.

Sub-processors

Third-party services that may process client data on our behalf. Updated as our infrastructure evolves.

Supabase (Lovable Cloud)
Managed database, authentication, storage, edge functions
AWS. Us-east-1
PayPal
Payment processing (Live Orders v2, USD)
Global
Google Workspace
Business email and document collaboration
Global
Resend
Transactional email delivery (receipts, intelligence briefings)
Global
Google Analytics
Aggregated, anonymized website analytics
Global
Vercel / Lovable
Edge hosting and CDN
Global

Data Retention

How long different categories of data are kept.

Active intelligence reports
Retained for the duration of access (180 days on Tiers 1–2, continuously on Enterprise).
Expired tier data
Read-only for 90 days after access expiration, then archived.
Archived data
Encrypted and retained for 12 months unless deletion is requested.
Account & billing records
Retained for 7 years to meet US/EU tax and compliance obligations.
Deletion requests
Honored within 30 days of verified request to security@geosystemsai.com.

Data Processing Agreement

A standard DPA with EU Standard Contractual Clauses is available for all paid tiers and is countersigned for Enterprise subscriptions.

Request DPA →

Responsible Disclosure

Report suspected vulnerabilities to our security team. We respond within 2 business days and work in good faith with researchers acting in good faith.

security@geosystemsai.com →

Procurement, security, or compliance questions?

Our security team responds to vendor assessments, DPA requests, and procurement questionnaires within 2 business days.