Security
Last updated: October 2, 2026
1. Our approach
Geolyti stores your company profile, competitor names, monitoring results, and drafted content. It does not store payment card numbers, and it never publishes anything on your behalf. This page describes the controls in place today. Where a detail is still being confirmed, we say so rather than guess.
2. Encryption
In transit. All traffic to Geolyti is served over HTTPS. We accept TLS 1.2 and TLS 1.3 only, with modern AEAD cipher suites, and send an HSTS header so browsers refuse to downgrade. Certificates are issued and renewed automatically.
At rest. Passwords are stored only as salted hashes. Customer data lives in PostgreSQL. [Placeholder — confirm the encryption-at-rest mechanism (disk or volume encryption) for the database and backups before publishing.]
3. Hosting and region
The application, database, and cache run as containers on dedicated infrastructure. Only the web edge is reachable from the internet; the database, cache, and workers are on a private network. [Placeholder — name the hosting provider and region(s) before publishing.]
4. Subprocessors
We use the following third parties to deliver the Service. The same list appears in our Privacy Policy. We do not sell customer data or use it to train any model we operate.
- Paddle.com Market Limited — Payment processing, billing, tax handling, and subscription management, as merchant of record for paid subscriptions.
- Anthropic — Content Studio generation, and answer monitoring on Claude.
- Google (Gemini) — Answer monitoring on Gemini.
- OpenAI — Answer monitoring on ChatGPT.
- Perplexity — Answer monitoring on Perplexity.
- Microsoft Clarity — Cookieless, masked page-interaction analytics: clicks, scrolling, and mouse movement. Text on the page and anything you type are masked before anything leaves your browser.
- Google (Sign in with Google) — Optional sign-in; only if you choose it.
- Infrastructure and hosting providers — Host the application, database, and backups that store your account and company data.
5. Access control
Authentication. Sign-in issues a short-lived access token (15 minutes) and a refresh token (7 days) that rotates on every use. Every API endpoint requires a valid token by default; the few public endpoints opt out explicitly.
Authorization. Data is scoped to your company. Within a company, teammates hold one of three roles: owner, editor, or viewer. Only owners can invite people or change roles. The one server-to-server endpoint, which completes Google sign-in, is guarded by a separate secret compared in constant time.
Abuse protection. Sensitive endpoints are rate limited, and login attempts are limited per IP at the edge.
6. Backups and logs
The database is dumped with pg_dump and the most recent 14 dumps are retained. Application and edge logs are kept for 30 days and exclude query strings, which can carry one-time codes. [Placeholder — confirm backup frequency, off-site copy, and restore testing before publishing.]
7. Security incidents
If we confirm an incident affecting your data, we will notify the affected account owners by email without undue delay, describe what happened and what data was involved, and tell you what we are doing about it. Where we act as your processor, notification terms are set out in the DPA. [Placeholder — insert the committed notification window (for example, 72 hours) during legal review.]
To report a vulnerability or a suspected incident, write to security@geolyti.com.
8. Data Processing Agreement
If you need a DPA for GDPR or similar requirements, our template covers processing scope, subprocessors, international transfers, and incident notification.
The template is being finalised with counsel. To receive it now, email privacy@geolyti.com.