Security & Trust

Best-in-class governance — without surrendering your data.

GOVERNTIQ deploys inside your security perimeter and reads your APIs, databases, logs, consent records and file shares with read-only credentials you issue. This page — and the one-pager — answer what security, risk and procurement teams ask first.

What leaves your perimeter — and what never does

Leaves (metadata only)

Kinds of personal data and how many, per column, endpoint, log source or file sample; retention, access and encryption flags; severities, clause references and scores; masked samples and salted fingerprints.

Never leaves

Database rows, log messages, file contents, consent identifiers, prompts, model weights, connection strings and tokens, and your application data. Evidence documents are fingerprinted in your browser and stay with you.

Read-only, one credential per source

Each connector uses a credential you issue for that source alone. The scanner never writes, deletes or changes a setting, and anything the credential cannot see is reported as not evaluated.

SourceCredential you issueWhat leaves
APIsRead access to the application endpoints you name (a bearer token you scope)Field names, kinds and counts
DatabasesA read-only database roleColumn names, kinds, counts, masks, safeguard flags — never a row or the connection string
Log platformsA read token for your log platformRetention days, flags, kinds and counts — never a message
Consent storesA read credential for your consent manager or consent APIRatios and counts — never an identifier
File shares & bucketsA mounted path or a read-only storage tokenCounts, ages, flags, kinds — never a file

Security guarantees

✓

Your data stays put

GOVERNTIQ reads data, models, logs, consents and files in place. Only findings leave — kinds, counts, masked samples, flags and scores. Rows, messages, file contents, prompts, model weights and credentials never do.

✓

Outbound-only, no inbound ports

The scanner is an HTTPS client — it never opens a listener. It deploys behind your firewall with no inbound rules, through a forward proxy, or fully air-gapped.

✓

Least privilege, one credential per source

A read-only database role, a log-platform token, a consent-API credential, a bucket read token — each issued and scoped by you and revocable at any time. A separate run token from your portal authorises reporting and can be cut off instantly. The scanner never writes.

✓

Auditable before it sends

Dry-run mode performs the full scan and prints the exact payload without transmitting — your security team reviews it before reporting is enabled.

✓

Encrypted & tamper-evident

TLS with certificate verification by default; mTLS and pinning for high-assurance deployments. Evidence is hash-chained and WORM-anchored so it cannot be silently altered.

✓

Hardened build option

For high-assurance / air-gapped environments, a compiled, hardware-bound scanner build with license attestation runs only where you authorise it.

Deploys the way your security team requires

OPTION 1

On-premises

Run the scanner on your own servers, inside your own network. Nothing is required to reach the public internet beyond reporting findings to your chosen GOVERNTIQ endpoint.

OPTION 2

Private cloud / VPC

Deploy in your cloud tenant with your security groups, egress controls and secrets management. The scanner honours your proxy and certificate policy.

OPTION 3

Air-gapped

Fully disconnected operation: the scanner measures locally and reports to an in-network GOVERNTIQ endpoint, or runs offline and syncs when a connection is allowed. No outbound internet needed.

Framework alignment

India DPDP Act 2023 + Rules 2025 · GDPR · EU AI Act · DORA · ISO/IEC 27001 · ISO/IEC 42001 & 42005 · SOC 2 · NIST AI RMF · HIPAA · Saudi PDPL · SAMA CSF · SDAIA AI Ethics · UAE PDPL · DIFC DP Law · ADGM DPR · UAE financial-sector AI guidance · UAE AI Charter

GOVERNTIQ is architected to SOC 2 and ISO/IEC 27001 control objectives and produces the tamper-evident evidence those audits require. Formal attestation reports and penetration-test summaries are available under NDA on request.