Security & privacy

How Governly protects your vendor documentation

This page is maintained by the Governly team to answer common security and privacy questions about the platform. It describes practices and controls that are in place today, and is not a substitute for independent certification.

Data protection

  • All uploaded documents are encrypted in transit using TLS.
  • All uploaded documents are encrypted at rest.
  • Customer data is never used to train AI models.
  • Uploaded files are processed only for the requested assessment.

Data residency

  • Data is stored within the EU.
  • Data processing locations are clearly identified.
  • EU-based sub-processors are prioritised wherever possible.

Retention

  • Documents are automatically deleted after a configurable retention period.
  • Option for immediate deletion after report generation (planned feature).
  • Retention windows are documented and reviewable.

Compliance support

  • Designed to support GDPR.
  • Designed to support ISO/IEC 27001.
  • Designed to support NIS2.
  • Designed to support DORA.
  • Aligns with internal governance frameworks.

Shared responsibility

Governly provides the platform, infrastructure controls and processing logic. Customers are responsible for the lawful collection of vendor documentation, for sharing only data appropriate to the assessment, and for reviewing the generated decision pack with their information security, legal and procurement stakeholders before relying on it.