Platform Live v4.0.0
SOC 2 Type II Observation underway
Patent Pending USPTO filing, June 2026
ISO 42001 Target Q2 2027
GDPR Compliant DPA available on request

TRUST & SECURITY

Security, compliance, and transparency — built into the architecture.

Govrnix governs enterprise AI from the outside. That means our own security posture must meet the standard we enforce for others. Here is how we do it.

Security Certifications

Govrnix is building toward the certification stack required for regulated enterprise procurement. Current status of each certification is shown below.


SOC 2 Type II
IN PROGRESS
Observation period commenced June 2026. Independent audit scheduled December 2026. Covers Security, Availability, and Confidentiality trust service criteria.
ISO 42001 — AI Management System
TARGET Q2 2027
AIMS framework established June 2026. ISO 42001 is the international standard for AI management systems — the AI governance equivalent of ISO 27001.
Patent Pending
FILED
Patent Pending, USPTO filing June 2026, covering Circuit Breaker™ enforcement, Score Manipulation Detection, and Cryptographic Attribution Chain.
Penetration Test
SCHEDULED Q1 2027
Independent third-party penetration test of all API endpoints, authentication systems, and Command Center scheduled for Q1 2027.

Data Architecture

Govrnix is architected so that customer data never leaves the customer's own environment. This is not a policy — it is a structural guarantee.


🔒
ZERO DATA RETENTION
All governance evidence is written directly to the customer's own data environment. Govrnix does not retain copies of customer data beyond the milliseconds required to process each governance event.
🔐
ENCRYPTION
AES-256 encryption at rest via all storage providers. TLS 1.2+ encryption in transit on all API endpoints. SHA-256 cryptographic sealing on every governance event.
🔑
BRING YOUR OWN KEY (BYOK)
All LLM inference uses the customer's own API key. Govrnix never transmits customer data through shared LLM accounts. Customer data stays in the customer's AI environment.
🛡️
CRYPTOGRAPHIC AUDIT TRAIL
Every governance decision — approval, warning, or block — is sealed with a SHA-256 hash including timestamp, decision context, risk score, and regulatory mapping. Tamper-evident by design.
🔍
API AUTHENTICATION
All API endpoints require authenticated access. Rate limiting enforced. Session tokens expire automatically. No unauthenticated access to governance data.
📋
SOC 2 EVIDENCE AUTOMATION
Daily automated evidence collection via GitHub Actions. Deployment logs, access records, and configuration snapshots collected and written to the SOC 2 evidence vault.

Regulatory Compliance Coverage

Govrnix maps every governance event to applicable regulatory frameworks automatically. These are the frameworks covered.


GDPR
Data Processing Agreement available on request. Zero retention architecture. SCCs for EU transfers.
EU AI Act
Conformance Declaration in place. High-risk AI system controls implemented. Regulatory mapping automated.
NIST AI RMF
GOVERN, MAP, MEASURE, and MANAGE functions implemented across the platform.
ISO 42001
AIMS framework established. Certification target Q2 2027. AI lifecycle controls documented.
SR 11-7
Model risk management controls for financial services AI deployments. Automated evidence generation.
Colorado AI Act
Effective January 1, 2027 (as amended by SB 26-189). Scoped to employment-related AI decisions. Notice and adverse-action controls tracked ahead of effective date.

Security Documentation

The following documents are available to enterprise customers and prospects on request. Contact info@govrnix.com with your organization name and the documents required.


Data Processing Agreement (DPA)
GDPR-compliant DPA covering processing scope, sub-processors, security measures, and data subject rights
ON REQUEST
Sub-processor List
Complete list of third-party sub-processors with data categories, locations, and certifications
ON REQUEST
Service Level Agreement (SLA)
Uptime commitments, support response times, and service credit terms by subscription tier
ON REQUEST
Incident Response Policy
P1–P4 incident classification, 72-hour breach notification commitment, response procedures
ON REQUEST
Vulnerability Disclosure Policy
Responsible disclosure process, safe harbor provisions, and coordinated disclosure timeline
PUBLIC
AIMS Framework (ISO 42001 Aligned)
Artificial Intelligence Management System covering risk protocols, ethical principles, impact assessments, and lifecycle controls
ON REQUEST
Information Security Policy
Internal security controls, access management, and operational security standards
ON REQUEST

Security Contact


Request security documentation or report a concern

For security documentation requests, vendor security questionnaires, data processing agreements, or to report a security concern — contact us directly. We respond to all security inquiries within 48 hours.

INFO@GOVRNIX.COM