Security at Govantic

Your data never leaves your environment. That's not a feature - it's our architecture.

Single-tenant by design

Govantic deploys entirely inside your own cloud account. AI reasoning, agent signals, and compliance data stay within your environment. No data ever transits our infrastructure.

Your Cloud, Your Data

The AI reasoning engine and all Supervision Agents run inside your own cloud account. Customer data is never stored on or routed through Govantic-managed servers.

Encryption Everywhere

All data is encrypted in transit (TLS 1.3) and at rest (AES-256). Passwords are cryptographically hashed and never stored in plaintext.

Workspace Isolation

Each customer operates in a completely isolated Workspace. Cross-tenant access is architecturally impossible - enforced at every layer of the application.

Role-Based Access Control

Three granular roles (Admin, Manager, Viewer) with permissions enforced at the API layer. Email domain restrictions control who can join your Workspace.

Enterprise-grade from day one

JWT Authentication

Token-based authentication with automatic refresh mechanisms. Session tokens stored in browser local storage with secure defaults.

Audit Logging

All administrative actions are logged with timestamps, user identity, and action details. Full audit trail for compliance reporting.

Secrets Management

All sensitive values (database credentials, API keys, JWT secrets) are stored in AWS Secrets Manager. Never hardcoded, never in environment variables.

Network Security

Application services run in private subnets with no direct internet access. All inbound traffic routes through a load balancer with TLS termination.

Your data, your rules

We believe compliance tools should practice what they preach. Here's how we handle your data.

Data Ownership

You own your data. Period. We never acquire ownership rights in Customer Data. Your policies, SOPs, frameworks, and evidence belong to you.

Data Portability

Export your data at any time during your subscription. After termination, data remains available for export for 30 days.

No Data Selling

We do not sell, rent, or trade personal information to third parties. Ever. We may use aggregated, anonymized data to improve the platform.

GDPR & CCPA Ready

Full support for data subject rights including access, rectification, erasure, and portability. Standard Contractual Clauses for international transfers.

Retention Controls

Configure retention policies appropriate for your compliance requirements. Free tier retains evidence for 7 days; paid plans offer full control.

Transparency

Our Privacy Policy and Terms of Service are written in plain language. No surprises. Read them at the links below.

Found a vulnerability?

We take security seriously. If you've discovered a security vulnerability, please report it responsibly.

Report to security@govantic.com

Security isn't a feature.
It's how we're built.

Questions about our security practices? We're happy to talk.