Trust

Governly trust posture

This page is maintained by the Governly team and describes how we operate the platform: how we respond to incidents, how we protect data through backups and disaster recovery, and how customers reach us on security matters. It is not an independent audit report.

Incident response

Governly maintains a documented incident response process. The customer-facing summary below is intentionally short; the full runbook is an internal document and is available under NDA.

  • Detect: platform monitoring and customer reports feed a single triage queue.
  • Classify: confirmed incidents affecting customer data are declared and severity is assigned.
  • Contain and remediate: engineering and security work through a documented runbook.
  • Notify: affected customer administrators are notified without undue delay via email.
  • Review: every declared incident is followed by a written post-incident review.

To report a suspected security incident affecting Governly, email security@governly.se.

Backup & disaster recovery

Governly's backup and continuity posture is inherited from our managed infrastructure provider and extended with our own operational routine.

  • The managed database is backed up by our infrastructure provider on a continuous basis with point-in-time recovery.
  • Uploaded evidence files are stored in the managed object store with the same regional redundancy as the database.
  • Restore procedures are documented and exercised as part of our operational routine.
  • Specific RPO and RTO commitments are contractual and are shared under NDA on request.

Service availability

Current platform health is published on our Status page. Availability targets for paid tiers are stated in the applicable order form or master agreement.

Related pages