Frequently asked questions

Quick answers about data protection, accuracy and how Governly fits into your existing vendor risk programme.

What is Requirements-to-Evidence Mapping?+

Requirements-to-Evidence Mapping is Governly's methodology for vendor due diligence: every customer requirement is mapped to verifiable evidence inside the vendor's own documentation — SOC 2 reports, ISO 27001 certificates, DPAs, security policies and architecture — with source citations and an evidence strength rating.

What if I don't have a requirements catalogue yet?+

You can start from the Recommended Enterprise Baseline — a professionally curated starting point for vendor due diligence maintained by Governly across information security governance, identity and access, encryption, logging, incident management, business continuity, privacy and data protection, data residency, sub-processors, certifications and exit. It is built around common enterprise vendor due diligence practices and designed to cover the areas organisations commonly evaluate before approving a software supplier. It is not intended to replicate any single compliance framework such as ISO 27001, SOC 2 or NIS2 and should instead be viewed as a professionally curated starting point that you remain free to customise. It is one of three equal starting points alongside uploading your own (Excel, CSV, paste) or building from scratch. The Baseline is fully editable from the first interaction to reflect your own policies, regulatory obligations and risk appetite — your assessment owns its own snapshot.

What is evidence-based vendor due diligence?+

Evidence-based vendor due diligence verifies vendor claims against published evidence instead of relying on questionnaire answers. Governly automates this by mapping your requirements to the supporting evidence and flagging gaps, conflicts and recommended follow-up questions.

How is customer data protected?+

Uploaded documents are encrypted in transit with TLS 1.2+ and encrypted at rest. Access is strictly scoped to the processing required for your assessment, with role-based access control and full audit logging across the platform.

Is customer data used to train AI models?+

No. Customer documents and assessment data are never used to train AI models. Uploads are processed solely to generate your decision pack and are not shared with any model provider for training.

What documents can be assessed?+

Typical inputs include Data Processing Agreements (DPA), ISO/IEC 27001 certificates and Statements of Applicability, SOC 2 Type I/II reports, security white papers, sub-processor lists and vendor-provided security questionnaires (PDF, DOCX).

Where is customer data stored?+

Customer data is stored within the EU. Processing locations are clearly identified and EU-based sub-processors are prioritised wherever possible. See the Security Statement for current infrastructure details.

How long are documents retained?+

Uploaded documents and generated reports are retained only as long as needed to deliver and support your assessment, and are deleted according to the retention period documented in the Privacy Policy. You can request earlier deletion at any time.

Can reports be exported?+

Yes. Every decision pack can be exported as a PDF that can be attached to procurement tickets, change-management records or audit trails.

Is this legal advice?+

No. Governly provides decision support and risk assessment assistance. Final decisions should be reviewed by your information security, legal and procurement stakeholders.

How accurate are the assessments?+

Assessments are designed to support — not replace — human decision making. Each report includes a confidence score and explicit evidence gaps so reviewers can validate findings before approving a vendor.

Which frameworks does Governly support?+

Governly is designed to support organisations working with GDPR, ISO/IEC 27001, SOC 2, NIS2, DORA and internal governance frameworks.

What does a typical decision pack include?+

Executive summary, risk rating, composite score, domain scoring, key findings, evidence gaps, recommended actions and a final recommendation. See the downloadable sample report on the homepage.