Security & Compliance

Enterprise-Grade Security

Your financial data deserves bank-level protection. We take security seriously so you can focus on growth.

Certifications & Compliance

SOC 2 Type II

Audited controls for security, availability, and confidentiality

Compliant

GDPR

Full compliance with EU data protection regulations

Compliant

CCPA

California Consumer Privacy Act compliance

Compliant

HIPAA Ready

Available for healthcare-related use cases

Available

Security Features

Data Protection

  • AES-256 encryption at rest
  • TLS 1.3 encryption in transit
  • Field-level encryption for sensitive data
  • Automatic data backup with 99.99% durability

Access Control

  • Role-based access control (RBAC)
  • Multi-factor authentication (MFA)
  • Single sign-on (SSO) support
  • Session management and auto-logout

Infrastructure

  • Hosted on AWS with SOC 2 certified data centers
  • Multi-region redundancy
  • DDoS protection and WAF
  • 99.9% uptime SLA

Monitoring & Response

  • 24/7 security monitoring
  • Real-time threat detection
  • Incident response team on standby
  • Automated vulnerability scanning

How We Handle Your Data

Your Data Stays Yours

We never sell, share, or use your data for purposes other than providing our services. You retain full ownership.

Right to Deletion

Request deletion of your data at any time. We will permanently remove all your information within 30 days.

Data Portability

Export all your data in standard formats. Your analyses, reports, and insights are always accessible.

Minimal Data Collection

We only collect data necessary to provide our services. No tracking beyond essential product analytics.

Security FAQ

Where is my data stored?

All data is stored in AWS data centers in the United States (us-east-1) with optional EU storage for GDPR requirements. Data is encrypted at rest using AES-256.

Who has access to my financial documents?

Only you and users you explicitly grant access to can see your documents. Our engineering team cannot access customer data without explicit permission and audit logging.

How long do you retain my data?

Active account data is retained indefinitely. Upon account deletion, all data is permanently removed within 30 days. Backup copies are purged within 90 days.

Do you have a bug bounty program?

Yes, we maintain a responsible disclosure program. Security researchers can report vulnerabilities to security@geogrowthai.com.

Can I get a Data Processing Agreement (DPA)?

Yes, we provide DPAs for enterprise customers. Contact sales@geogrowthai.com to request a signed DPA.

Have Security Questions?

Our security team is here to help. Reach out for security assessments, DPAs, or any compliance questions.