GOVERNTIQ deploys inside your security perimeter and reads your APIs, databases, logs, consent records and file shares with read-only credentials you issue. This page — and the one-pager — answer what security, risk and procurement teams ask first.
Kinds of personal data and how many, per column, endpoint, log source or file sample; retention, access and encryption flags; severities, clause references and scores; masked samples and salted fingerprints.
Database rows, log messages, file contents, consent identifiers, prompts, model weights, connection strings and tokens, and your application data. Evidence documents are fingerprinted in your browser and stay with you.
Each connector uses a credential you issue for that source alone. The scanner never writes, deletes or changes a setting, and anything the credential cannot see is reported as not evaluated.
| Source | Credential you issue | What leaves |
|---|---|---|
| APIs | Read access to the application endpoints you name (a bearer token you scope) | Field names, kinds and counts |
| Databases | A read-only database role | Column names, kinds, counts, masks, safeguard flags — never a row or the connection string |
| Log platforms | A read token for your log platform | Retention days, flags, kinds and counts — never a message |
| Consent stores | A read credential for your consent manager or consent API | Ratios and counts — never an identifier |
| File shares & buckets | A mounted path or a read-only storage token | Counts, ages, flags, kinds — never a file |
GOVERNTIQ reads data, models, logs, consents and files in place. Only findings leave — kinds, counts, masked samples, flags and scores. Rows, messages, file contents, prompts, model weights and credentials never do.
The scanner is an HTTPS client — it never opens a listener. It deploys behind your firewall with no inbound rules, through a forward proxy, or fully air-gapped.
A read-only database role, a log-platform token, a consent-API credential, a bucket read token — each issued and scoped by you and revocable at any time. A separate run token from your portal authorises reporting and can be cut off instantly. The scanner never writes.
Dry-run mode performs the full scan and prints the exact payload without transmitting — your security team reviews it before reporting is enabled.
TLS with certificate verification by default; mTLS and pinning for high-assurance deployments. Evidence is hash-chained and WORM-anchored so it cannot be silently altered.
For high-assurance / air-gapped environments, a compiled, hardware-bound scanner build with license attestation runs only where you authorise it.
Run the scanner on your own servers, inside your own network. Nothing is required to reach the public internet beyond reporting findings to your chosen GOVERNTIQ endpoint.
Deploy in your cloud tenant with your security groups, egress controls and secrets management. The scanner honours your proxy and certificate policy.
Fully disconnected operation: the scanner measures locally and reports to an in-network GOVERNTIQ endpoint, or runs offline and syncs when a connection is allowed. No outbound internet needed.
India DPDP Act 2023 + Rules 2025 · GDPR · EU AI Act · DORA · ISO/IEC 27001 · ISO/IEC 42001 & 42005 · SOC 2 · NIST AI RMF · HIPAA · Saudi PDPL · SAMA CSF · SDAIA AI Ethics · UAE PDPL · DIFC DP Law · ADGM DPR · UAE financial-sector AI guidance · UAE AI Charter
GOVERNTIQ is architected to SOC 2 and ISO/IEC 27001 control objectives and produces the tamper-evident evidence those audits require. Formal attestation reports and penetration-test summaries are available under NDA on request.