Draft for counsel review — not yet in force. This policy is a working draft published for transparency while a formal policy is finalized. It accurately describes what the platform does with data today but has not been reviewed by counsel. Questions: [email protected] or the contact page.
GovSecure AI is operated by [LEGAL ENTITY]. This policy covers the govsecure-ai.com website and the GovSecure AI platform. It does not claim compliance with any specific privacy certification or framework; it describes actual practice so your counsel and privacy office can evaluate it.
We use this data to operate the platform (authentication, tenant scoping, document generation, evidence management), to enforce plan entitlements and process billing, to maintain security and auditability, to respond to inquiries, and to monitor service health. We do not sell personal data.
When you use AI features, relevant compliance context you have submitted (for example control descriptions and evidence metadata) is sent to Anthropic's Claude models to generate control mappings, narratives, gap analyses, and risk suggestions. Outputs are schema-validated and require human review before use. Each AI interaction is recorded in the audit log with its prompt version and token counts, and AI usage is metered against your plan.
The following third parties process data on our behalf:
A current sub-processor list is available on request via the contact page.
Deleting records in the platform is a soft delete: the record is marked deleted and excluded from normal use, but retained because compliance artifacts must remain reconstructable. Audit logs and the evidence ledger are append-only by design and are not rewritten by deletion requests. Purge of soft-deleted data and end-of-contract retention are governed by your ordering document; absent one, data is retained for [RETENTION PERIOD] after account closure.
You can review and update account information in the platform, change cookie preferences via the footer link, and contact us to access, correct, or request deletion of personal data (subject to the retention behavior above). We will describe applicable legal rights in the counsel-reviewed version of this policy rather than assert them here.
Material changes to this draft will be reflected on this page. Contact: [LEGAL ENTITY], [ADDRESS], [email protected], or the contact page.