Security at GEO by MyFast.ai
You are trusting us with your business information and with a line of code on your live website. Here is exactly how both are handled — in plain language, with no claims we cannot back up.
How we protect your account
Encrypted connections everywhere
Every page, dashboard action and API call on geo.myfast.ai is served over HTTPS with TLS. Data moving between your browser and our platform is encrypted in transit.
Passwords are hashed, never stored in plain text
Account passwords are hashed with bcrypt before they are saved. Nobody at MyFast.ai — including our own team — can read your password, and we will never ask you for it.
Session-based authentication with role separation
Logins are handled by a signed, session-based authentication layer. Client accounts and administrator accounts are separated by role, and every dashboard route and data API checks your session before returning anything.
We never see or store your card details
All payments are processed by Stripe. Card numbers are entered directly with Stripe and never touch our servers or our database. Billing changes and cancellations run through the Stripe customer portal.
Your business data is scoped to your account
Your onboarding details, content library and visibility results are tied to your account and are only used to run your GEO campaign. We do not sell your data, and we do not share it with other clients.
A snippet you stay in control of
The publishing snippet is a single line of JavaScript that renders your content on your own domain. It is read-only for your site — it does not need CMS credentials, database access or admin logins. Remove the line, or switch publishing off in your dashboard, and content stops immediately.
What we do not claim
We would rather be straight with you than decorate this page with badges. GEO by MyFast.ai does not currently hold a SOC 2, ISO 27001 or PCI certification of its own — card data is handled entirely by Stripe, which does maintain those certifications. If your organization has a specific security or compliance requirement, call us on 1-888-332-6649 and we will tell you honestly whether we can meet it.
Security questions we get asked
Does the snippet need access to my CMS or hosting account?
No. You paste one line of JavaScript before the closing </head> tag, or add it through Google Tag Manager. We never ask for WordPress, Shopify, Webflow, Squarespace or hosting credentials, and we do not have write access to your site.
Can I remove the snippet later?
Yes, at any time. Delete the line of code from your site or switch publishing off in your dashboard and new content stops appearing instantly. There is no penalty and no lock-in.
Where are my payment details stored?
With Stripe. Card details are entered directly with Stripe and are never stored on MyFast.ai servers. We keep only the subscription status needed to run your account.
Who can see my business data?
Your data is scoped to your own account and used to produce your content and visibility reports. Access is limited to authorized MyFast.ai personnel who need it to operate the service. We do not sell your data or share it with other clients.
What happens to my data if I cancel?
You can cancel anytime from your dashboard. As set out in our Privacy Policy, records are retained for up to 90 days after an account is deactivated in case you want to reactivate, after which data may be permanently removed. You can request deletion of your personal data at any time by emailing [email protected].
Report a security concern
If you believe you have found a vulnerability or have a security question about your account, email [email protected] or call 1-888-332-6649 — we are open 24/7.