Trust & security
Cadastral records, infrastructure networks, customer locations. Here is exactly how GeoPilot protects them, with no marketing fog.
How we protect your data
Six controls that ship for every customer on every tier. Not toggles, not upsells.
Sign in with Google or GitHub. No passwords stored, no password database to leak. Two-factor enforcement is delegated to your identity provider and honored through the OAuth flow.
Projects, members, audit rows, connections, all gated by row-level security. A bug in app code cannot cross the tenant boundary.
When you connect your own Postgres or PostGIS, the password is encrypted before it ever reaches our database. Per-row IV, authenticated tag, versioned ciphertext.
v1:base64(iv||ct||tag)TLS 1.2+ everywhere with HSTS preload-eligible. AES-256 at rest. Strict referrer, MIME-sniff blocked, framing denied by default.
Every public dashboard URL is a random token pinned to a frozen snapshot. New links expire after 90 days. Revoke any link and it stops resolving immediately.
Every org mutation writes a row capturing who, what, when, and from where. IPs truncated to /24 (IPv4) or /48 (IPv6) so household identity is not retained.
Built on
We name our subprocessors so you can verify the underlying compliance posture.
App hosting and edge compute
SOC 2 Type II · ISO 27001Postgres, auth, object storage
SOC 2 Type II · HIPAALarge file and snapshot storage
SOC 2 · ISO 27001/27017/27018Error monitoring
SOC 2 Type IIProduct analytics (optional, EU-host)
SOC 2 Type IIPayments (India market)
PCI DSS Level 1Secure development
Static analysis, dependency monitoring, and required review on every change to production.
GitHub CodeQL with the security-extended query pack runs on every pull request and weekly against the existing codebase. Findings block merge until triaged.
Dependabot watches npm and GitHub Actions weekly. Security advisories raise an immediate PR; routine bumps are grouped to keep noise low.
All production code lands through a pull request with a passing CI check and a reviewer signoff on the main branch. No direct pushes to production.
You own your data and the outputs we generate. You can leave with everything you brought, plus the work you did here.
We would rather be honest about gaps than oversell. If any of these block your procurement, talk to us about Enterprise.
Responsible disclosure
We respond within one business day and credit researchers who give us a reasonable window to fix before publishing. Disclosure policy is also published per RFC 9116.
security@smartbhujal.com