Last updated: July 22, 2026
Security
We build theogeo.ai to keep your data safe by default. This page explains the concrete measures we take to protect your account and audit data, the trusted providers we build on, and how to report a security issue. For how we collect and use data, see our Privacy Policy.
How we protect your data
- Encryption in transit. All traffic between your browser and our servers is encrypted over HTTPS/TLS. We do not serve the application over unencrypted connections.
- Encryption at rest. Your data is stored in a managed Postgres database (Supabase) that encrypts data at rest.
- Tenant isolation. Every customer's data is separated using row-level security in the database, so one account cannot read another account's data.
- Least-privilege access. Privileged database credentials are used only on our servers and are never exposed to the browser or shipped in client code.
Authentication
- We sign you in with a one-time magic link or Google sign-in (OAuth). We do not ask you to create a password, so there is no password for us to store or for an attacker to steal.
- Sign-in uses the secure PKCE flow, and sessions are managed with short-lived, httpOnly authentication cookies.
- Access to the dashboard is enforced centrally for every protected route, not page by page.
Payments
Payments are processed entirely by Stripe, a PCI-DSS Level 1 certified payment provider. Card numbers and bank details never touch our servers — we only store your Stripe customer ID and subscription status so we can manage your plan.
We collect as little as possible
The less we hold, the less there is to protect. We do not collect:
- IP addresses
- Browser or device fingerprints
- Location data
- Advertising, analytics, or third-party tracking cookies of any kind
We use only the essential cookies required to keep you signed in. We never sell your data and never share your audit results with other customers.
Trusted providers (sub-processors)
We build on established infrastructure and service providers — such as Supabase (database & auth), Stripe (payments), Sentry (error monitoring), and the AI engines we query on your behalf. Each is a recognized provider that maintains its own independent security program (for example SOC 2 and/or ISO 27001). The complete list of providers, what each is used for, and the data shared with them is published in our Privacy Policy.
Reliability & monitoring
- Our database platform performs automated backups so your data can be recovered.
- We monitor the application for errors and exceptions in production so we can detect and fix problems quickly.
- The audit pipeline is designed to be resilient: a failure in one AI engine never blocks the rest of your audit.
Your data, your control
You can request a copy of your data, correct it, or delete it at any time. When you delete your account, all associated data is permanently removed. See Your Rights in the Privacy Policy, or email [email protected].
Compliance
We honor data-subject rights consistent with GDPR and CCPA/CPRA, including access, deletion, correction, and portability. We are not yet SOC 2 certified. Enterprise customers evaluating theogeo.ai are welcome to reach out to discuss our security posture and current roadmap — we're happy to complete security questionnaires.
Reporting a vulnerability
If you believe you've found a security vulnerability, please tell us privately at [email protected] before disclosing it publicly. We'll acknowledge your report, investigate promptly, and keep you updated. We appreciate the work of the security community and will not pursue action against good-faith research that respects our users' privacy and avoids service disruption.
Contact
For security questions, email [email protected]. For privacy and data requests, email [email protected].