Security & trust

Trust is not a feature. It is the product.

GovIQ helps public bodies make procurement decisions that have to survive audit, challenge and Tribunal review. The platform is built on an immutable audit chain, a database hosted in Dublin, Ireland, and an ISO 27001 management system working towards certification.

Certification roadmap

Where we stand, stated plainly.

StandardStatusTarget
ISO/IEC 27001:2022Not certified — working towards certificationCertification programme in progress; no certificate date published
GDPR / Data Protection Act 2018CompliantOngoing — annual review
EU AI Act (Reg. 2024/1689)Tracked — GovIQ currently ships no AI featuresOngoing — annual review
NIS2 alignment (via healthcare sector)Overlay in developmentPosition statement Q4 2026
Security posture

How we protect data.

Identity & access

Microsoft Entra ID SSO with mandatory MFA and Conditional Access; role-based permissions; quarterly access reviews.

Encryption

TLS 1.3 in transit; AES-256 at rest; HSM-backed key management inherited from our hosting sub-processors.

Tenant isolation

Multi-tenant by design with application-layer enforcement, covered by automated tests on every change.

Immutable audit chain

Every state change recorded in a tenant-scoped SHA-256 chained log; chain integrity verified on a schedule.

Backups & DR

Convex-managed snapshots. RTO ≤ 4h and RPO ≤ 24h are targets; the first restore drill is pending.

Data residency

Customer data is stored in AWS eu-west-1 (Dublin, Ireland). A deliberately small sub-processor list, each under a DPA, with SCCs for US-parented providers. No AI processes customer data.

Documents on request

Evidence for your due diligence.

The full sub-processor list, certification roadmap, incident-response process and vulnerability-disclosure policy live in the trust centre. The Trust Profile PDF and ISO 27001 programme evidence packs are available under NDA — email privacy@goviq.ie. We acknowledge security reports within one working day.

Get started

Do your due diligence before you commit.