Trust & subprocessors
Who touches your data,
and what each one holds.
Every third party that processes data on Govern360's behalf, what it handles, and where its attestations are published - alongside a plain statement of what Govern360 itself has certified and what it has not.
A subprocessor is a third party that processes customer data on Govern360's behalf. This page lists every one, what it handles, and where its own attestations are published. It is updated when the list changes.
Govern360's own position
Subprocessors
Netlify
Serves the marketing site, the tenant console and the staff console, and runs the serverless functions that talk to connected platforms. Application code and static assets only.
- Data processed
- No customer records at rest. Function execution is transient.
- Attestations
- SOC 2 Type II, ISO/IEC 27001, GDPR. Published at their trust centre.
- Trust centre
- trust-center.netlify-corp.com
Supabase
The primary data store. Holds the agent inventory, policies, evidence records, audit chain and user accounts. Every table is protected by row-level security scoped to the organisation.
- Data processed
- All customer records held by Govern360.
- Attestations
- SOC 2 Type II, HIPAA. Postgres hosted on AWS.
- Trust centre
- supabase.com/security
Anthropic
Powers the AI Analysis button. Invoked only when a person clicks it - nothing is sent in the background. See the data-flow note below for exactly what is included.
- Data processed
- A short summary string. May include agent, system and vendor names with their status and risk labels, capped at twelve items. Never prompt content, never end-user conversations.
- Attestations
- SOC 2 Type II. Zero data retention available on the commercial API.
- Trust centre
- trust.anthropic.com
Stripe
Handles subscription and metered billing. Govern360 code never touches card details - payment data is entered directly into Stripe's hosted fields.
- Data processed
- Billing contact and subscription state. No cardholder data reaches Govern360.
- Attestations
- PCI DSS Level 1, SOC 1 and SOC 2 Type II.
- Trust centre
- stripe.com/docs/security
Postmark
Sends console invitations and notification email. No marketing or bulk sending.
- Data processed
- Recipient email address and the message body.
- Attestations
- SOC 2 Type II, GDPR. Part of ActiveCampaign.
- Trust centre
- postmarkapp.com/security
GitHub
Read-only access through a GitHub App, used to report Copilot seat allocation and usage. Installed per organisation and revocable there at any time.
- Data processed
- Seat counts and aggregate usage metrics. No repository content and no source code.
- Attestations
- SOC 1 and SOC 2 Type II, ISO/IEC 27001.
- Trust centre
- github.com/security
What leaves your tenant
The AI Analysis button on each console page sends a short summary to Anthropic so it can be read back in plain language. That summary may include agent, system and vendor names alongside their status and risk labels, capped at twelve items per request. It never includes prompt content, end-user conversations, document contents, or credentials.
It runs only when a person clicks the button. Nothing is sent in the background, on a schedule, or during discovery.
Connected sources, which are not subprocessors
Govern360 reads from platforms an organisation already runs. Data flows from those platforms into Govern360, not the other way, so they are sources rather than subprocessors - but they are listed because the distinction matters less to a reader than knowing what is connected.
Microsoft Graph and Power Platform
Read-only, through an app registration consented by a tenant administrator. Used to discover agents, environments, connectors, tool definitions and Copilot consumption. Govern360 requests read scopes; it does not request write access, and enforcement artifacts are applied by administrators in their own platforms.
Microsoft Purview
Read-only, for data classification and DLP signal. Where a scope has not been granted, the affected surface reports that it could not read rather than showing an empty result as a clean one.
Cloud provider cost APIs
Read-only, for AI spend attribution. Credentials are held encrypted and are used only for the reads the connection was established for.
Questions this page is meant to answer
Where is our data held?
In Supabase - Postgres hosted on AWS - protected by row-level security scoped to your organisation. Netlify serves the application and runs functions; it holds no customer records at rest.
Does Govern360 have SOC 2?
Not yet. It is architected to SOC 2 controls and the audit is in progress. The subprocessors above are independently certified, which is a separate matter.
Does our data train an AI model?
No. AI Analysis calls a commercial API for a summary; it is not used for training. Nothing else in the product sends customer data to a model provider.
Can we see this list change?
Yes. Ask privacy@aivons.com to be notified when a subprocessor is added or removed.
Attestations listed for each subprocessor are those the subprocessor publishes; verify them at the linked trust centre rather than relying on this page. For a copy of Govern360's security documentation, contact legal@aivons.com.