Skip to main content
GeoFolks

Security and data scope

We distinguish safeguards implemented in the application from commitments that require infrastructure, documentation, or contract evidence.

Application and measurement layers Encrypted credentials and TLS Roles, 2FA, and operation audit
Visualization for the page: Security and data scope
Accountability

Application and measurement layers

The application, queues, and measurement services have separate responsibilities in code and deployment configuration. Customer-data access is limited by company scope and roles.

Service separation alone does not prove physically separate infrastructure. Production-environment details should be documented for the actual deployment.

Organisational fact

Encrypted credentials and TLS

Provider and integration credentials use encrypted application fields. Public traffic should be served over HTTPS/TLS at deployment level.

We do not claim column-level encryption for all data or key separation without production-configuration evidence. Cryptographic parameters should be confirmed in environment documentation.

Organisational fact

Roles, 2FA, and operation audit

The workspace enforces company membership roles, resource authorisation, invitations, and optional two-factor authentication. Important operations are stored in the audit log.

Permission-review frequency and administrator-access rules are organisational processes. They require procedural evidence, not merely website copy.

Organisational fact

External providers

Measurements and platform functions may use model, payment, email, hosting, and observability providers configured for production.

The current subprocessor list, purpose, and processing region should come from a maintained legal document. The repository alone does not prove that a complete list is published.

Organisational fact

Region follows deployment

Storage and processing regions depend on the database, storage, queues, and external providers actually used.

The client workspace does not offer data-region selection. Any EEA or transfer claim must be supported by production configuration and legal documentation.

Organisational fact

Data sent to models

A measurement request contains the question, brand name, aliases, market, language, and configured competitors. It should not contain confidential end-customer data.

Provider-side retention and training rules depend on the contract and endpoint used. They must be checked for each active provider.

Organisational fact

Retention, export, and deletion

The application includes retention configuration, a command enforcing retention periods, account-data export, and GDPR request handling. Deletions are permission-controlled and audited.

Backup retention and final deletion outside the application database depend on infrastructure. They should be described in the applicable policy.

Organisational fact

Incident register

The admin panel includes an incident lifecycle and update timeline. It can store state, communications, and action history.

Notification deadlines, on-call coverage, and root-cause analysis are operational procedures. They require a team and runbook; an interface alone does not execute them.

Organisational fact

Backup and recovery require evidence

The repository contains storage, retention, and monitoring assumptions, but does not prove that a production restore test has been completed.

We do not claim a public status page, RTO, RPO, or regular restore tests without current infrastructure reports.

Organisational fact

GDPR-supporting functions

The platform supports export, account deletion, data-subject requests, operation logging, and retention settings. These functions support compliance duties.

Legal compliance also depends on configuration, documentation, and organisational practice. We do not present application features as certification.

Organisational fact

DPA requires publication

A DPA should define party roles, data scope, subprocessors, retention, and safeguards. It is a legal document, not a code feature.

We do not claim a contact-free download until a current, dated version is actually available on the site.

Organisational fact

Verification before response

The team can receive security questions through contact or support and prepare an answer based on current configuration.

We do not claim a ready questionnaire download unless it has been published and verified by an accountable person.

Next step

Verify security practices

We distinguish safeguards implemented in the application from commitments that require infrastructure, documentation, or contract evidence.