Security
Last updated: 18 July 2026
We take the security of your account and data seriously. Here’s an overview of the measures built into ActiveGeo.
1. Access control
ActiveGeo is invite-only. Accounts must be approved before they can reach the workspace or API, and access can be suspended at any time. Admin tooling is restricted to authorised staff.
2. Credential protection
Passwords are hashed, API keys are stored only as hashes, and any AI provider keys you add (BYOK) are encrypted at rest. Secret fields are never exposed through our API.
3. Abuse prevention
We apply rate limiting, per-account and daily usage caps, disposable-email blocking, and IP-aware throttling to protect the Service from automated abuse and to keep it available for everyone.
4. Data in transit and at rest
Traffic is served over HTTPS. Sensitive values are encrypted at rest, and access to production systems is limited.
5. Responsible disclosure
If you believe you’ve found a security issue, please tell us via our contact page before disclosing it publicly, and give us a reasonable chance to fix it.