Skip to main content
Geta.ai
Enterprise-grade security

Security & Trust

Your data's protection is our top priority, backed by independent audits, not just promises.

SOC 2 Type IIISO 27001GDPR Ready

Certifications & Compliance

SOC 2 Type II

SOC 2 Type II

Annual third-party audit of our security, availability, and confidentiality controls

ISO 27001

ISO 27001

Certified information security management system

GDPR Ready

GDPR Ready

Data processing agreements, consent management, and right-to-erasure workflows built in

Infrastructure Security

  • Hosted on AWS with multi-region redundancy
  • TLS 1.2+ encryption in transit; AES-256 encryption at rest
  • VPC isolation with private subnets for all data stores
  • Regular automated backups with point-in-time recovery
  • DDoS protection via AWS Shield

Application Security

  • Annual penetration testing by a third-party security firm
  • OWASP Top 10 vulnerability assessments
  • Dependency scanning and automated SAST/DAST in CI/CD pipeline
  • Role-based access control (RBAC) with least-privilege enforcement
  • Multi-factor authentication (MFA) for all internal systems

Data Privacy

  • We do not sell, rent, or share customer data with third parties for marketing purposes.
  • Customer contact data is logically isolated per tenant.
  • Data residency options available for Enterprise customers (India, EU, US).
  • Retention policies configurable per account.

Incident Response

  • 24/7 security monitoring with automated alerting.
  • Documented incident response playbooks.
  • Customer notification within 72 hours of any confirmed breach affecting their data (GDPR-aligned).

Found a vulnerability, or have a security question?

If you discover a security vulnerability, report it to us directly. We acknowledge every report within 24 hours and keep you informed as we investigate. General security questions are welcome too.

security@geta.ai