Privacy Policy
Effective . Version 2026-09-08. This policy covers govsecure-ai.com and the GovSecure AI service.
Who is responsible for your data
The service is operated by GovSecure AI and can be reached at [email protected]. We determine how account, billing, website, and support data is used to operate our business. For personal data in an organization's workspace, that organization determines the purpose of processing and we process it on its instructions under our Data Processing Addendum. Contact your organization administrator first about workspace access or content.
Information we collect
- Accounts: name, email, organization, role, credentials in protected form, authentication factors, sign-in information, and agreement acceptance.
- Workspace content: system records, controls, evidence files and metadata, generated documents, POA&M items, and content supplied to AI features or connected integrations.
- Security and operations: IP addresses, browser information, request and activity records, timestamps, audit events, and error information.
- Billing: billing contact, Stripe customer and subscription identifiers, payment status, and plan usage. Stripe collects payment details at checkout; we do not store full card numbers.
- Support: contact details and messages you send us, including organization information supplied in inquiries.
- Cookies: essential session and preference information, plus optional analytics where enabled and consented to. See our Cookie Policy.
Why we use information
We use information to create and secure accounts, provide workspace features, process subscriptions, enforce plan limits, answer requests, investigate abuse, maintain service reliability, and comply with legal obligations. Optional analytics help us understand website use after consent. Where a law requires a legal basis, we rely on performing our contract, our legitimate interests in operating and securing the service, legal obligations, or consent for optional analytics, as applicable. We do not sell personal information or share it for cross-context behavioral advertising.
AI features
When you request AI assistance, relevant submitted context, such as control descriptions, evidence metadata, and narrative text, is sent to Anthropic to generate a response. We record usage and audit metadata, including prompt versions and token counts. Do not include sensitive personal data or information your organization has not authorized for this processing. AI responses require human review. We do not use customer workspace content to train our own general-purpose AI models. Provider processing remains subject to the provider's applicable service terms; this policy does not promise zero retention by external providers.
Service providers and other disclosures
- InsForge: database and evidence storage infrastructure, payment integration, and managed transactional email delivered through Amazon SES.
- Railway: application hosting and operational infrastructure.
- Cloudflare: network delivery, DNS, and website protection.
- Stripe: checkout, subscription billing, and payment administration.
- Anthropic: AI processing when you request AI features.
- Inngest: background workflow execution and event processing where enabled.
- Resend: an alternative transactional email provider when configured.
- Google Tag Manager and Analytics: optional website analytics, loaded only after analytics consent when configured.
Providers receive the information needed for their function. Your organization's authorized members and invited assessors can access information within their permissions. Integrations you connect process data according to the access you authorize. We may also disclose information when required by law, to protect rights and safety, or in a business transfer subject to appropriate confidentiality and notice obligations.
Security and processing locations
The service uses encrypted transport, password hashing, access controls, tenant-scoped data access, optional multifactor authentication, and audit records. Evidence processing includes content hashes, versioning, and malware-scan status controls. No system is completely secure. GovSecure AI does not hold a FedRAMP authorization and this policy does not promise a certification or dedicated government hosting environment.
We use United States infrastructure and providers that may process information in other countries. We do not promise exclusive processing in a particular region. Where a restricted international transfer requires additional safeguards, those arrangements must be established before the affected data is submitted; accepting these online terms alone does not establish a transfer mechanism.
Retention, account closure, and deletion
Workspace records are retained while needed to provide your account and requested services. Some in-app deletions mark records as deleted without removing the underlying data. Audit and evidence-ledger records are append-only in ordinary operation. Cancelling billing or reaching the end of a trial does not automatically delete data, and the service does not currently apply a fixed automatic account-purge period.
Request account closure, return, or permanent deletion through our contact email. After verifying authority, we will coordinate the request, explain any information that must be retained and why, and apply applicable legal deadlines. We retain billing, security, dispute, and legal records only for as long as reasonably necessary for those purposes or as required by law. Backups and audit records may need a separate removal process; their existence does not eliminate applicable deletion rights. Customer data processing remains subject to the Data Processing Addendum and any signed agreement.
Your rights and choices
Depending on applicable law, you may request access, correction, deletion, a portable copy, restriction of processing, or object to processing. You may withdraw optional analytics consent through Cookie Preferences in the footer. Withdrawal does not affect earlier lawful processing. You may also complain to your applicable privacy regulator. We verify identity and, where relevant, an agent's authorization before acting and do not discriminate against you for exercising privacy rights. If we decline a request, you can ask us to review that decision at the same contact address.
This is a service for adult professional users, not children. Do not submit children's information. Contact us if you believe a child has supplied information to the service. Send privacy requests to [email protected]. For organization-controlled workspace data, we may refer your request to its administrator.
Policy updates
We update the effective date and version when this policy changes and provide notice of material changes through the service or account email. Where required, we obtain consent before using previously collected data for a new purpose. Questions can also be sent through our contact page.