Security Measures | Geodd
Last Updated: 9th June, 2026

Security Measures

01

Security Overview

Geodd designs its Services to minimize customer data exposure, limit unnecessary access, and protect systems used to provide AI infrastructure services.

Geodd’s Services include:

  • Inferencing
  • Serverless Inferencing
  • Dedicated Inferencing
  • Dedicated GPU
  • Bare Metal Infrastructure

For AI model API services, Geodd processes prompts, inputs, outputs, request bodies, and response bodies transiently to provide the requested inference response. Unless separately agreed in writing, Geodd does not store API prompts, API inputs, API outputs, completions, API request bodies, API response bodies, uploaded files, embeddings, customer datasets, or fine-tuning data.

Geodd does not use API data for model training and does not conduct human review of prompts or outputs by default.

02

Data Minimization

Geodd applies data minimization principles to reduce the amount of Customer Personal Data stored or retained.

For AI model API services, Geodd’s default handling is:

Data TypeDefault Handling
API prompts / inputsNot stored
API outputs / completionsNot stored
API request bodiesNot stored
API response bodiesNot stored
Uploaded filesNot supported / not stored unless separately agreed
EmbeddingsNot stored unless separately agreed
Customer datasetsNot stored unless separately agreed
Fine-tuning dataNot supported unless separately agreed
API data used for trainingNo
Human review of prompts / outputsNo, by default
API payload cachingNo

Geodd may retain limited metadata for billing, usage measurement, security, troubleshooting, service operation, fraud prevention, legal, and compliance purposes.

Limited metadata may include:

  • Model used
  • Timestamp
  • Token count
  • Status code
  • Usage records
  • IP address, where applicable
  • Authentication metadata
03

Encryption

Geodd uses encryption measures designed to protect data in transit and at rest.

Security measures include:

  • TLS protection for data in transit
  • Encryption at rest where applicable
  • Encryption of personal data at rest where applicable
  • Backup encryption where applicable
  • API key hash storage
  • No storage of full API keys

Customer API keys are the responsibility of the Customer. Geodd does not store the full API key. Geodd stores only a hash of the API key for authentication and security purposes.

04

Authentication and Access Control

Geodd uses authentication and access control measures to limit access to systems and data.

Security measures include:

  • API authentication using API keys and OAuth where applicable
  • Role-based access controls
  • MFA for administrative access
  • Staff access limited based on job role and operational need
  • Access logging
  • Confidentiality obligations for personnel

Access to systems is limited to authorized personnel who need access for support, security, debugging, service operations, billing, legal, compliance, or other legitimate operational purposes.

05

Network and Infrastructure Security

Geodd uses network and infrastructure controls designed to protect the Services and reduce unauthorized access risks.

Security measures may include:

  • Firewalls
  • Web application firewall protection
  • Private networks where applicable
  • Access controls for administrative systems
  • Customer isolation through dedicated endpoints where applicable
  • Secure service configuration
  • Infrastructure monitoring where applicable

For Dedicated Inferencing, customer isolation may be provided through dedicated endpoints or other technical controls.

For Dedicated GPU and Bare Metal Infrastructure, security responsibilities may depend on the service configuration and whether Geodd or the Customer controls the relevant applications, workloads, credentials, datasets, models, and access permissions.

06

Customer Isolation

Geodd supports customer isolation through dedicated endpoints where applicable.

For Dedicated Inferencing, Geodd may provision dedicated AI model endpoint infrastructure for Customer’s inference workloads.

For Dedicated GPU and Bare Metal Infrastructure, Customer may receive dedicated infrastructure for its workloads. Where Customer controls applications, models, datasets, credentials, or access permissions on that infrastructure, Customer is responsible for configuring and securing those components appropriately.

07

Logging and Monitoring

Geodd uses logging and monitoring to support security, troubleshooting, service operation, billing, compliance, and abuse prevention.

Logging and monitoring measures may include:

  • Access logging
  • Security logging
  • Usage metadata collection
  • Monitoring of service availability and performance
  • Operational logs for troubleshooting and debugging
  • Records used for billing, fraud prevention, legal, and compliance purposes

Geodd does not store API request bodies or API response bodies by default.

08

Vulnerability Management

Geodd maintains vulnerability management processes designed to identify and address security risks.

Measures may include:

  • Risk-based vulnerability review
  • Security updates and patching where applicable
  • Review of relevant service, infrastructure, and dependency risks
  • Remediation based on severity, exploitability, and operational impact

Geodd may update its vulnerability management practices over time as the Services, infrastructure, and risk environment evolve.

09

Incident Response

Geodd maintains an incident response process to assess, manage, and respond to security incidents.

Measures may include:

  • Internal escalation procedures
  • Security investigation and containment steps
  • Assessment of affected systems and data
  • Remediation planning
  • Customer notification where required under the Data Processing Agreement or applicable law
  • Post-incident review where appropriate

For Personal Data Breaches affecting Customer Personal Data, Geodd will notify Customer without undue delay and, where feasible, within 72 hours after becoming aware of the breach, as described in Geodd’s Data Processing Agreement.

Security contact: [email protected].

10

Backups and Retention

Geodd uses backups for relevant user and usage data where applicable.

Backup and retention measures include:

  • 30-day rolling backups for users and usage data where applicable
  • Backup deletion through normal backup expiry cycles
  • Retention of billing and financial usage records where required for legal, tax, billing, fraud prevention, security, dispute, and compliance purposes
  • Retention of security logs for 12 months unless longer retention is required
  • Deletion of account data within 30 days after account deletion, except for lawful retained records and backup expiry

API prompts, API inputs, API outputs, request bodies, and response bodies are not stored by default and therefore are not available for export, correction, or deletion after processing.

11

Personnel Security

Geodd applies personnel security measures to limit unnecessary access to Customer Personal Data and operational systems.

Measures include:

  • Staff confidentiality obligations
  • Access limited based on job role and operational need
  • Administrative MFA
  • Role-based access controls
  • Access logging where applicable
  • Security and operational awareness appropriate to job responsibilities

Personnel access is limited to what is necessary for support, security, debugging, service operations, billing, legal, compliance, and related operational needs.

12

Support and Administrative Access

Support and administrative access may occur where necessary for:

  • Customer support
  • Security
  • Debugging
  • Service operations
  • Billing
  • Legal obligations
  • Compliance
  • Abuse or fraud prevention

Support/admin access may occur from operational locations used by Geodd, including Sri Lanka, where necessary for support, security, debugging, service operations, billing, legal, and compliance.

Safeguards include:

  • MFA
  • Role-based access controls
  • Access logging
  • Encryption
  • Confidentiality obligations
  • Staff training
  • Transfer safeguards where applicable
13

Subprocessor and Vendor Controls

Geodd uses vendors and subprocessors to support the Services.

Geodd is implementing a vendor and subprocessor review process that may include review of:

  • Data Processing Agreements
  • Security terms
  • Transfer safeguards
  • Subprocessors
  • Data locations
  • Certifications where available
  • Vendor security practices

Geodd’s Subprocessor List is available at: geodd.io/legal/subprocessors.

14

Physical Infrastructure Suppliers

Geodd may use third-party suppliers for physical hardware, rack space, power, cooling, connectivity, physical maintenance, and physical security.

Geodd does not treat physical infrastructure suppliers as subprocessors unless they process Customer Personal Data on behalf of Geodd.

Physical infrastructure suppliers are not treated as subprocessors where they do not have logical, administrative, operational, support, storage, backup, monitoring, encryption-key, or readable access to Customer Personal Data, workloads, prompts, outputs, logs, backups, storage, or runtime environments.

Emergency access by physical infrastructure suppliers is limited to physical premises, rack, cabling, power, hardware replacement, cooling, connectivity, and physical security. It does not include logical access to systems, workloads, storage, logs, encryption keys, or Customer Personal Data.

15

International Access and Transfer Safeguards

Geodd LLC is established in the United States.

For EU customers, API inference is hosted in EU data center infrastructure by default. EU/UK customers may also choose non-EU infrastructure, in which case API requests may be routed outside the EU/UK for inference processing.

Where Customer Personal Data is transferred to or accessed from a country that has not been recognized as providing an adequate level of protection, Geodd uses transfer safeguards as described in its Data Processing Agreement.

These may include:

  • EU Standard Contractual Clauses
  • UK International Data Transfer Addendum
  • Swiss FADP adaptations where applicable
  • Transfer Impact Assessment support
  • Supplementary technical and organizational measures

Supplementary measures may include TLS encryption in transit, encryption at rest where applicable, API key hash storage, role-based access controls, MFA for administrative access, firewalls and WAF, private networks where applicable, customer isolation through dedicated endpoints, access logging, vulnerability management, incident response processes, staff confidentiality obligations, and access limited based on job role and operational need.

16

Customer Responsibilities

Security is a shared responsibility between Geodd and Customer.

Customer is responsible for:

  • Keeping API keys and credentials secure
  • Managing access permissions for its users and systems
  • Selecting the appropriate infrastructure region
  • Configuring its applications, models, datasets, workloads, and credentials securely where Customer controls them
  • Ensuring that Customer Personal Data may lawfully be submitted to the Services
  • Avoiding unnecessary submission of sensitive or regulated data
  • Using the Services in accordance with applicable law, the Agreement, and Geodd’s policies

Where Customer uses Dedicated GPU or Bare Metal Infrastructure, Customer may have additional responsibilities depending on the level of control Customer has over workloads, applications, models, data, credentials, and access permissions.

17

Changes to Security Measures

Geodd may update its security measures over time as the Services, infrastructure, and security environment evolve.

Geodd will not materially reduce the overall level of protection for Customer Personal Data during the term of the applicable Agreement.

18

Contact

For security questions, contact: [email protected]

For privacy questions or data protection requests, contact: [email protected]