AI Transparency Statement
Last updated: August 2026
Governly uses automated analysis to support vendor assessment and decision-making processes. This page explains how we apply that technology, what it does on your behalf and the boundaries we keep around your data.
Assessment results are intended as decision-support material and should be reviewed by appropriate business, security, compliance and legal stakeholders before approval decisions are made.
Decision support, not decision making
Assessment reports are intended as structured decision support. Business owners, security, compliance and legal stakeholders remain responsible for the final decision.
Your documents are never used to train models
Uploaded vendor documentation is processed only to generate the assessment you requested. It is never used to train, fine-tune or improve any AI model — ours or a third party's.
Human review is encouraged
We recommend that every assessment is reviewed by the appropriate function in your organisation — typically information security, procurement, compliance or legal — before approval decisions are recorded.
Bounded, auditable analysis
Automated analysis is scoped to the documents and context you provide. Each report links findings to the documentation that triggered them, so reviewers can audit the reasoning.
The Recommended Enterprise Baseline is curated, not AI-generated
The Recommended Enterprise Baseline is a set of vendor due diligence requirements designed and maintained by Governly. It is not produced by a language model. AI is used to analyse the vendor's evidence against the requirements you choose — never to author the requirements themselves.
What automated analysis does
Governly extracts and structures information from the documents you provide, compares it against common control areas (data protection, access management, business continuity, sub-processors, certifications, and incident response) and produces an executive summary, risk rating, key findings, missing-information gaps and recommended actions.
What it does not do
Governly does not issue regulatory certifications, replace internal audit functions or constitute legal advice. Reports do not authorise the procurement of a vendor on their own; they are inputs to your governance process.
Data handling
Uploaded documents are stored in access-controlled storage, processed only for the assessment you request, and retained according to the principles described in our Privacy Policy. See the Security Statement for details on encryption, residency and access controls.
Contact
Questions about how we use automated analysis? Email info@governly.se.