Security controls designed around isolation and auditability.
Govarna stores AI inventories, governance evidence, and questionnaire content. This page describes controls visible in the current architecture without claiming a certification or absolute security.
Managed transport and storage
Govarna is served over HTTPS. Customer records and uploads use managed database and object-storage services, with provider-managed protection for stored data.
Row-level isolation
Customer records use database-level row-level security policies tied to organization membership and role. Application queries also scope customer content by organization where the workflow requires it.
Append-only audit-log privileges
State-change paths write audit entries through a server-only service role. Database grants give authenticated users read access only when an organization-admin policy allows it; application roles have no update or delete grant on audit rows.
Server-side privileged credentials
Privileged service, billing, and AI-provider credentials are read only in server-side code and deployment configuration. Browser code uses public client configuration and authenticated sessions instead of service credentials.
Private file buckets
Evidence and source-questionnaire uploads are stored in non-public buckets. Storage policies use an organization identifier in each object path and restrict writes or deletion by membership role.
Responsible disclosure
Report a suspected vulnerability to security@govarna.com with reproduction steps and potential impact. Please avoid accessing, changing, or retaining data that is not yours.
Sample data — format preview
Review a sample audit package
This PDF is built with sample data to show the export format. It is not a Govarna certification, audit opinion, customer report, or evidence of regulatory compliance.
Compliance posture
Privacy operations
Privacy questions and individual-rights requests can be sent to privacy@govarna.com. Scope, identity, authority, and applicable requirements are reviewed before action is taken.
Compliance tooling, not an attestation
Govarna uses deterministic rules for its core EU AI Act risk-tier workflow and organizes related evidence. Outputs support human review; they do not establish a customer's legal status or compliance.
Certification status
Govarna does not claim SOC 2 or ISO certification on this page. Any assurance reports or certifications held by infrastructure providers belong to those providers and are not Govarna attestations.
Data handling
Your policies, evidence, and questionnaire content are used only to draft your own answers and build your own evidence packs — never shared across customer accounts. Govarna does not train models on customer content. AI-assisted drafting calls our configured AI provider’s API server-side (see our AI Safety & Transparency Statement for the current provider path); provider-side handling is governed by our configured account terms, and current contractual details are available from security@govarna.com.
Subprocessors
Services referenced in current code paths. Which services receive data for a given customer depends on the feature used and deployment configuration. Reviewed 22 July 2026. Questions or change notifications: security@govarna.com.
| Subprocessor | Purpose | Data categories | Region |
|---|---|---|---|
| Vercel | Application hosting and CDN | Site traffic, request metadata | Global edge; compute in US/EU |
| Supabase | Database, authentication, file storage | Customer records, uploads, credentials | Configured project region |
| Anthropic | AI drafting and questionnaire extraction | Submitted questionnaire text, selected drafting context | United States |
| Stripe | Billing and payments | Billing contact and payment details | Global (US-based) |
| Resend | Transactional email | Email address, message content | United States |
| Loops | Marketing and lifecycle email | Email address, signup and tool-usage attributes | United States |
| Google Analytics | Website analytics (consent-gated) | Usage data, device metadata | Global |
| PostHog | Product analytics | Usage events, device metadata | US/EU cloud |
| Sentry | Error tracking | Error reports, request metadata | United States |
| Axiom | Log management | Application logs (no raw client IPs in tool paths) | United States |
| Upstash | Rate limiting | Hashed identifiers, counters | Global |
Need our security questionnaire response?
Email security@govarna.com with your security-review questions.
To ask whether DPA or service-level materials are available for a purchase, contact us directly. This public page does not create contractual commitments.
Start 14-day free trial