Governly trust posture
This page is maintained by the Governly team and describes how we operate the platform: how we respond to incidents, how we protect data through backups and disaster recovery, and how customers reach us on security matters. It is not an independent audit report.
Incident response
Governly maintains a documented incident response process. The customer-facing summary below is intentionally short; the full runbook is an internal document and is available under NDA.
- Detect: platform monitoring and customer reports feed a single triage queue.
- Classify: confirmed incidents affecting customer data are declared and severity is assigned.
- Contain and remediate: engineering and security work through a documented runbook.
- Notify: affected customer administrators are notified without undue delay via email.
- Review: every declared incident is followed by a written post-incident review.
To report a suspected security incident affecting Governly, email security@governly.se.
Backup & disaster recovery
Governly's backup and continuity posture is inherited from our managed infrastructure provider and extended with our own operational routine.
- The managed database is backed up by our infrastructure provider on a continuous basis with point-in-time recovery.
- Uploaded evidence files are stored in the managed object store with the same regional redundancy as the database.
- Restore procedures are documented and exercised as part of our operational routine.
- Specific RPO and RTO commitments are contractual and are shared under NDA on request.
Service availability
Current platform health is published on our Status page. Availability targets for paid tiers are stated in the applicable order form or master agreement.
Related pages
- • Security & privacy — encryption, residency, retention and compliance posture.
- • Sub-processors — infrastructure and service providers.
- • Data Processing Agreement — scope and how to request a signed copy.
- • AI Transparency — how AI is used and governed.