GOVIQ-TRUST-002 · v0.1 (DRAFT)
Trust at GovIQ
GovIQ helps Irish public bodies make better procurement decisions. Trust is not a feature for us — it is the product. This page tells you, in plain English, how we earn that trust: who we are, who we work with, how we protect data, and how to engage with us when something matters.
This page is live. The information below reflects the current state of GovIQ. Where something is in progress, we say so.
- Last meaningful update
- Next review
- Quarterly — alongside Management Review
- Privacy / GDPR
- privacy@goviq.ie
- Security disclosure
- security@goviq.ie
1.Where we are on our certification roadmap
| Standard | Status | Target |
|---|---|---|
| ISO/IEC 27001:2022 | Not certified — working towards certification | Certification programme in progress; no certificate date published |
| NIS2 alignment (essential-entity supplier through HSE) | Overlay in development | Position statement Q4 2026 |
| EU AI Act (Regulation (EU) 2024/1689) | Tracked — GovIQ currently ships no AI features, and no AI or LLM service processes customer data | Ongoing — annual review |
| GDPR / Data Protection Act 2018 | Compliant | Ongoing — annual policy review |
If you are evaluating GovIQ while our certification programme is in progress, ask us for the Trust Profile PDF (privacy@goviq.ie). It walks through the current state of every ISO/IEC 27001:2022 Annex A control in our ISMS.
2.Who runs security at GovIQ
| Role | Person |
|---|---|
| CEO + acting CISO + Data Protection Lead | Liam McDonagh |
| External lead auditor | Not yet engaged |
| Certification body | Not yet engaged (candidates: NSAI, BSI, LRQA, DNV) |
| External penetration tester | Not yet engaged |
Top management commitment to information security is signed by the CEO and ratified by the NED. Quarterly Management Reviews cover ISMS performance, audit results, incident response, and improvement actions.
3.Our sub-processors
We deliberately keep this list small. These are the only sub-processors that process customer data today. Each is covered by a Data Processing Agreement (DPA); for the US-parented providers, Standard Contractual Clauses (SCCs) cover any access from outside the EEA.
| Sub-processor | Service | Where processing runs |
|---|---|---|
| Microsoft Ireland Operations Ltd | Sign-in (Entra ID); Microsoft Graph / SharePoint only where you connect your own Microsoft 365 tenant | EU Data Boundary (Ireland) |
| Convex Inc. (US parent) | Managed database and serverless runtime for the GovIQ application | AWS eu-west-1 — Dublin, Ireland |
| Vercel Inc. (US parent) | Web application hosting (Next.js) | Server functions pinned to Dublin, Ireland (dub1) from our next production deployment; until then Washington DC, US (iad1). Static assets from Vercel's global edge network |
| Resend, Inc. (US parent) | Transactional email — recipient name and address, subject and full message content (invites, password resets, sign-in codes, award and regret letters); open and click tracking off | AWS eu-west-1 (Amazon SES) — Dublin, Ireland; sending domain mail.goviq.ie |
| Cloudflare, Inc. (US) | DNS resolution only — no customer personal data | Global anycast network (no EU region) |
Amazon Web Services acts as a sub-processor to Convex and Resend, not directly to GovIQ.
No AI processes customer data. The GovIQ product makes no AI / LLM calls, and no customer data is sent to any AI provider.
We give customers 30 calendar days' prior notice of any change to this list per our DPA, with a documented objection window.
4.Data protection
We hold ourselves to the GDPR and the Data Protection Act 2018, and we publish:
- A full Privacy Policy covering what data we collect, why, how long we keep it, and how to exercise your rights
- A Cookie Policy — minimal cookies, no marketing tracking, consent for any non-essential cookie
- A Record of Processing Activities (ROPA) maintained on both controller and processor sides, internally
- DPIAs for any feature that materially processes personal data — completed for our HSE pilot
- A personal data breach response process — within 72 hours notification to the Data Protection Commission where there is risk to data subjects, and within the HSE-DPA timing window for HSE-related incidents
Your rights under GDPR are at goviq.ie/privacy §8. To exercise any of them, email privacy@goviq.ie. Response within one month, no fee.
5.How we protect data — security posture
| Area | What we do |
|---|---|
| Identity & access | Microsoft Entra ID SSO with mandatory MFA and Conditional Access; role-based permissions in the platform; quarterly access reviews; documented joiner / mover / leaver flow |
| Encryption | TLS 1.3 in transit; AES-256 at rest (inherited from Convex / AWS / Vercel); key management by sub-processors with HSM-backed services |
| Tenant isolation | Multi-tenant by design with application-layer enforcement, covered by automated tests on every PR |
| Audit trail | Every state change in the platform is recorded in an immutable SHA-256 chained audit log; chain integrity is verified on a recurring schedule |
| Backups | Convex-managed snapshots (schedule and retention being confirmed); restore drill automated, first drill pending |
| Disaster recovery | RTO ≤ 4 hours, RPO ≤ 24 hours — targets, not yet verified by a restore drill; quarterly drills once the first has run |
| Vulnerability management | Dependabot, npm audit, patch SLAs per published policy; CVEs in stack are tracked and patched on schedule |
| Penetration testing | No external penetration test completed yet; an independent test is planned, and the report will be available to customers under NDA once complete |
| Endpoint security | Microsoft Intune MDM enrolment for every endpoint (rolling out Sprint 7 — September 2026) |
| Logging & monitoring | SIEM ingestion of audit and sign-in events (rolling out Sprint 7) |
| AI governance | Our AI Acceptable Use & Governance Policy covers internal staff use of AI tools. The GovIQ product currently ships no AI features and no AI or LLM service processes customer data; EU AI Act tracking is ongoing |
6.Incident response
If something goes wrong, here is what happens:
- We detect, internally or via your report
- We acknowledge the report and triage within hours
- We contain the incident
- We notify affected customers per their DPA timing — for HSE, within the contractually defined window
- We notify regulators where required (the DPC for personal data breaches, sectoral regulators as applicable)
- We eradicate the root cause and recover
- We run a post-incident review and update controls and policies
- We publish material lessons learned (without disclosing customer-specific detail) at the next Management Review
The full plan is in our Incident Response Policy (available on request under NDA).
7.Responsible vulnerability disclosure
If you've found a security issue with goviq.ie or the GovIQ platform, please tell us in confidence:
What to expect
- Acknowledgement within 1 working day
- Triage and initial response within 5 working days
- Coordinated disclosure timeline agreed with you
- Public credit if you would like it
- No legal action against good-faith researchers operating within scope
Out of scope: denial-of-service, social engineering of GovIQ personnel, physical attacks, attacks against third-party services (Microsoft, Convex, Vercel, etc.).
PGP key available on request.
8.How to ask us things
| You want to | Where to go |
|---|---|
| Read our privacy policy | goviq.ie/privacy |
| Read our cookie policy | goviq.ie/cookies |
| Ask a privacy / GDPR question | privacy@goviq.ie |
| Report a security vulnerability | security@goviq.ie |
| Receive our Trust Profile PDF | privacy@goviq.ie |
| Receive our ISO/IEC 27001 programme evidence or sub-processor evidence — under NDA | liam@goviq.ie |
| Discuss customer-specific feature opt-out or DPA amendment | liam@goviq.ie |
| Sales or product enquiries | info@goviq.ie |
| Lodge a complaint with the supervisory authority | Data Protection Commission (Ireland): dataprotection.ie |