Security & Trust

Security controls designed around isolation and auditability.

Govarna stores AI inventories, governance evidence, and questionnaire content. This page describes controls visible in the current architecture without claiming a certification or absolute security.

Managed transport and storage

Govarna is served over HTTPS. Customer records and uploads use managed database and object-storage services, with provider-managed protection for stored data.

Row-level isolation

Customer records use database-level row-level security policies tied to organization membership and role. Application queries also scope customer content by organization where the workflow requires it.

Append-only audit-log privileges

State-change paths write audit entries through a server-only service role. Database grants give authenticated users read access only when an organization-admin policy allows it; application roles have no update or delete grant on audit rows.

Server-side privileged credentials

Privileged service, billing, and AI-provider credentials are read only in server-side code and deployment configuration. Browser code uses public client configuration and authenticated sessions instead of service credentials.

Private file buckets

Evidence and source-questionnaire uploads are stored in non-public buckets. Storage policies use an organization identifier in each object path and restrict writes or deletion by membership role.

Responsible disclosure

Report a suspected vulnerability to security@govarna.com with reproduction steps and potential impact. Please avoid accessing, changing, or retaining data that is not yours.

Sample data — format preview

Review a sample audit package

This PDF is built with sample data to show the export format. It is not a Govarna certification, audit opinion, customer report, or evidence of regulatory compliance.

Open sample PDF

Compliance posture

Privacy operations

Privacy questions and individual-rights requests can be sent to privacy@govarna.com. Scope, identity, authority, and applicable requirements are reviewed before action is taken.

Compliance tooling, not an attestation

Govarna uses deterministic rules for its core EU AI Act risk-tier workflow and organizes related evidence. Outputs support human review; they do not establish a customer's legal status or compliance.

Certification status

Govarna does not claim SOC 2 or ISO certification on this page. Any assurance reports or certifications held by infrastructure providers belong to those providers and are not Govarna attestations.

Data handling

Your policies, evidence, and questionnaire content are used only to draft your own answers and build your own evidence packs — never shared across customer accounts. Govarna does not train models on customer content. AI-assisted drafting calls our configured AI provider’s API server-side (see our AI Safety & Transparency Statement for the current provider path); provider-side handling is governed by our configured account terms, and current contractual details are available from security@govarna.com.

Subprocessors

Services referenced in current code paths. Which services receive data for a given customer depends on the feature used and deployment configuration. Reviewed 22 July 2026. Questions or change notifications: security@govarna.com.

SubprocessorPurposeData categoriesRegion
VercelApplication hosting and CDNSite traffic, request metadataGlobal edge; compute in US/EU
SupabaseDatabase, authentication, file storageCustomer records, uploads, credentialsConfigured project region
AnthropicAI drafting and questionnaire extractionSubmitted questionnaire text, selected drafting contextUnited States
StripeBilling and paymentsBilling contact and payment detailsGlobal (US-based)
ResendTransactional emailEmail address, message contentUnited States
LoopsMarketing and lifecycle emailEmail address, signup and tool-usage attributesUnited States
Google AnalyticsWebsite analytics (consent-gated)Usage data, device metadataGlobal
PostHogProduct analyticsUsage events, device metadataUS/EU cloud
SentryError trackingError reports, request metadataUnited States
AxiomLog managementApplication logs (no raw client IPs in tool paths)United States
UpstashRate limitingHashed identifiers, countersGlobal

Need our security questionnaire response?

Email security@govarna.com with your security-review questions.

To ask whether DPA or service-level materials are available for a purchase, contact us directly. This public page does not create contractual commitments.

Start 14-day free trial