Trust is not a feature. It is the product.
GovIQ helps public bodies make procurement decisions that have to survive audit, challenge and Tribunal review. The platform is built on an immutable audit chain, a database hosted in Dublin, Ireland, and an ISO 27001 management system working towards certification.
Where we stand, stated plainly.
| Standard | Status | Target |
|---|---|---|
| ISO/IEC 27001:2022 | Not certified — working towards certification | Certification programme in progress; no certificate date published |
| GDPR / Data Protection Act 2018 | Compliant | Ongoing — annual review |
| EU AI Act (Reg. 2024/1689) | Tracked — GovIQ currently ships no AI features | Ongoing — annual review |
| NIS2 alignment (via healthcare sector) | Overlay in development | Position statement Q4 2026 |
How we protect data.
Identity & access
Microsoft Entra ID SSO with mandatory MFA and Conditional Access; role-based permissions; quarterly access reviews.
Encryption
TLS 1.3 in transit; AES-256 at rest; HSM-backed key management inherited from our hosting sub-processors.
Tenant isolation
Multi-tenant by design with application-layer enforcement, covered by automated tests on every change.
Immutable audit chain
Every state change recorded in a tenant-scoped SHA-256 chained log; chain integrity verified on a schedule.
Backups & DR
Convex-managed snapshots. RTO ≤ 4h and RPO ≤ 24h are targets; the first restore drill is pending.
Data residency
Customer data is stored in AWS eu-west-1 (Dublin, Ireland). A deliberately small sub-processor list, each under a DPA, with SCCs for US-parented providers. No AI processes customer data.
Evidence for your due diligence.
The full sub-processor list, certification roadmap, incident-response process and vulnerability-disclosure policy live in the trust centre. The Trust Profile PDF and ISO 27001 programme evidence packs are available under NDA — email privacy@goviq.ie. We acknowledge security reports within one working day.