GeoVector, operated by Zinc Labs Pte. Ltd. in Singapore, is committed to protecting customer data and operating its AI-powered platform responsibly. This page summarizes our current security, privacy, and AI-governance posture.
Compliance status
ISO/IEC 27001:2022 implementation is in progress with an external consultant; certification is targeted for Q4 2026. GeoVector is not currently SOC 2 certified. ISO/IEC 42001 is on our AI-governance roadmap. Our privacy practices are aligned with applicable Singapore PDPA and GDPR requirements; a Data Processing Addendum is available on request.
Infrastructure and data protection
GeoVector operates on managed cloud infrastructure and no physical servers or data centers. Primary data storage and processing are in Singapore: Supabase (AWS ap-southeast-1), Railway, and Google Cloud (asia-southeast1). Our web applications use Vercel's global edge network, with serverless functions executing in Singapore. Ephemeral collection workers may run in the United States and Thailand to gather AI-assistant responses and do not hold customer data at rest.
All public endpoints require TLS 1.2 or later. Managed providers encrypt data at rest with AES-256, and customer Google OAuth tokens are additionally encrypted before storage with AES-256-GCM.
Access control
We apply least-privilege access, require MFA on cloud-provider and source-control accounts, and use organization-scoped role-based access in the product. Customers can authenticate with a magic link, email and password, or Google sign-in.
Resilience and incident response
Our managed database receives automated daily backups with seven-day rolling retention, and we test restoration at least quarterly. For confirmed personal-data breaches, we notify affected customers without undue delay and within 72 hours of confirmation.
Service availability is published on our status page.
Privacy
We do not sell personal data, use it for advertising, or use customer data to train AI models. Data subjects and customers may request access, correction, deletion, portability, restriction, or objection at privacy@geovector.ai. We verify requests and target a response within 30 days.
See our Privacy Policy and Sub-processors. We publish at least 30 days' advance notice before a new sub-processor processes customer personal data.
Responsible AI
GeoVector uses commercial LLM APIs under terms in which provider training on submitted data is disabled. We do not train or fine-tune models on one customer's data for another customer's benefit. AI-generated content and recommendations are delivered as drafts and insights for human review; they are never automatically published to customer properties.
Documentation and contacts
Certain detailed documents β including the DPA template, Data Retention Schedule, Data Flow Map, and AI Data-Handling Transparency Note β are available on request under NDA where applicable.
For security questions, contact security@geovector.ai. For privacy questions or data-subject requests, contact privacy@geovector.ai.