GOVIQ-TRUST-002 · v0.1 (DRAFT)

Trust at GovIQ

GovIQ helps Irish public bodies make better procurement decisions. Trust is not a feature for us — it is the product. This page tells you, in plain English, how we earn that trust: who we are, who we work with, how we protect data, and how to engage with us when something matters.

This page is live. The information below reflects the current state of GovIQ. Where something is in progress, we say so.

Last meaningful update
Next review
Quarterly — alongside Management Review
Privacy / GDPR
privacy@goviq.ie
Security disclosure
security@goviq.ie

1.Where we are on our certification roadmap

StandardStatusTarget
ISO/IEC 27001:2022Not certified — working towards certificationCertification programme in progress; no certificate date published
NIS2 alignment (essential-entity supplier through HSE)Overlay in developmentPosition statement Q4 2026
EU AI Act (Regulation (EU) 2024/1689)Tracked — GovIQ currently ships no AI features, and no AI or LLM service processes customer dataOngoing — annual review
GDPR / Data Protection Act 2018CompliantOngoing — annual policy review

If you are evaluating GovIQ while our certification programme is in progress, ask us for the Trust Profile PDF (privacy@goviq.ie). It walks through the current state of every ISO/IEC 27001:2022 Annex A control in our ISMS.

2.Who runs security at GovIQ

RolePerson
CEO + acting CISO + Data Protection LeadLiam McDonagh
External lead auditorNot yet engaged
Certification bodyNot yet engaged (candidates: NSAI, BSI, LRQA, DNV)
External penetration testerNot yet engaged

Top management commitment to information security is signed by the CEO and ratified by the NED. Quarterly Management Reviews cover ISMS performance, audit results, incident response, and improvement actions.

3.Our sub-processors

We deliberately keep this list small. These are the only sub-processors that process customer data today. Each is covered by a Data Processing Agreement (DPA); for the US-parented providers, Standard Contractual Clauses (SCCs) cover any access from outside the EEA.

Sub-processorServiceWhere processing runs
Microsoft Ireland Operations LtdSign-in (Entra ID); Microsoft Graph / SharePoint only where you connect your own Microsoft 365 tenantEU Data Boundary (Ireland)
Convex Inc. (US parent)Managed database and serverless runtime for the GovIQ applicationAWS eu-west-1 — Dublin, Ireland
Vercel Inc. (US parent)Web application hosting (Next.js)Server functions pinned to Dublin, Ireland (dub1) from our next production deployment; until then Washington DC, US (iad1). Static assets from Vercel's global edge network
Resend, Inc. (US parent)Transactional email — recipient name and address, subject and full message content (invites, password resets, sign-in codes, award and regret letters); open and click tracking offAWS eu-west-1 (Amazon SES) — Dublin, Ireland; sending domain mail.goviq.ie
Cloudflare, Inc. (US)DNS resolution only — no customer personal dataGlobal anycast network (no EU region)

Amazon Web Services acts as a sub-processor to Convex and Resend, not directly to GovIQ.

No AI processes customer data. The GovIQ product makes no AI / LLM calls, and no customer data is sent to any AI provider.

We give customers 30 calendar days' prior notice of any change to this list per our DPA, with a documented objection window.

4.Data protection

We hold ourselves to the GDPR and the Data Protection Act 2018, and we publish:

  • A full Privacy Policy covering what data we collect, why, how long we keep it, and how to exercise your rights
  • A Cookie Policy — minimal cookies, no marketing tracking, consent for any non-essential cookie
  • A Record of Processing Activities (ROPA) maintained on both controller and processor sides, internally
  • DPIAs for any feature that materially processes personal data — completed for our HSE pilot
  • A personal data breach response process — within 72 hours notification to the Data Protection Commission where there is risk to data subjects, and within the HSE-DPA timing window for HSE-related incidents

Your rights under GDPR are at goviq.ie/privacy §8. To exercise any of them, email privacy@goviq.ie. Response within one month, no fee.

5.How we protect data — security posture

AreaWhat we do
Identity & accessMicrosoft Entra ID SSO with mandatory MFA and Conditional Access; role-based permissions in the platform; quarterly access reviews; documented joiner / mover / leaver flow
EncryptionTLS 1.3 in transit; AES-256 at rest (inherited from Convex / AWS / Vercel); key management by sub-processors with HSM-backed services
Tenant isolationMulti-tenant by design with application-layer enforcement, covered by automated tests on every PR
Audit trailEvery state change in the platform is recorded in an immutable SHA-256 chained audit log; chain integrity is verified on a recurring schedule
BackupsConvex-managed snapshots (schedule and retention being confirmed); restore drill automated, first drill pending
Disaster recoveryRTO ≤ 4 hours, RPO ≤ 24 hours — targets, not yet verified by a restore drill; quarterly drills once the first has run
Vulnerability managementDependabot, npm audit, patch SLAs per published policy; CVEs in stack are tracked and patched on schedule
Penetration testingNo external penetration test completed yet; an independent test is planned, and the report will be available to customers under NDA once complete
Endpoint securityMicrosoft Intune MDM enrolment for every endpoint (rolling out Sprint 7 — September 2026)
Logging & monitoringSIEM ingestion of audit and sign-in events (rolling out Sprint 7)
AI governanceOur AI Acceptable Use & Governance Policy covers internal staff use of AI tools. The GovIQ product currently ships no AI features and no AI or LLM service processes customer data; EU AI Act tracking is ongoing

6.Incident response

If something goes wrong, here is what happens:

  1. We detect, internally or via your report
  2. We acknowledge the report and triage within hours
  3. We contain the incident
  4. We notify affected customers per their DPA timing — for HSE, within the contractually defined window
  5. We notify regulators where required (the DPC for personal data breaches, sectoral regulators as applicable)
  6. We eradicate the root cause and recover
  7. We run a post-incident review and update controls and policies
  8. We publish material lessons learned (without disclosing customer-specific detail) at the next Management Review

The full plan is in our Incident Response Policy (available on request under NDA).

7.Responsible vulnerability disclosure

If you've found a security issue with goviq.ie or the GovIQ platform, please tell us in confidence:

security@goviq.ie

What to expect

  • Acknowledgement within 1 working day
  • Triage and initial response within 5 working days
  • Coordinated disclosure timeline agreed with you
  • Public credit if you would like it
  • No legal action against good-faith researchers operating within scope

Out of scope: denial-of-service, social engineering of GovIQ personnel, physical attacks, attacks against third-party services (Microsoft, Convex, Vercel, etc.).

PGP key available on request.

8.How to ask us things

You want toWhere to go
Read our privacy policygoviq.ie/privacy
Read our cookie policygoviq.ie/cookies
Ask a privacy / GDPR questionprivacy@goviq.ie
Report a security vulnerabilitysecurity@goviq.ie
Receive our Trust Profile PDFprivacy@goviq.ie
Receive our ISO/IEC 27001 programme evidence or sub-processor evidence — under NDAliam@goviq.ie
Discuss customer-specific feature opt-out or DPA amendmentliam@goviq.ie
Sales or product enquiriesinfo@goviq.ie
Lodge a complaint with the supervisory authorityData Protection Commission (Ireland): dataprotection.ie