← Back to Sign In

Security & Trust

GovernanceApp is built for company secretaries, corporate-services firms and in-house governance teams. Your entities, statutory registers, board records, and client information are among the most confidential data your firm holds — here is how we protect them.

🔐 Encrypted in transit & at rest 🔑 Passwordless sign-in 🧠 Never used to train AI ☁️ Built on certified Cloudflare infrastructure
Security isn't a page we wrote once — it's how the product is built. Every measure below is live in the platform today.
🔐

Encryption everywhere

All traffic is protected with TLS (HTTPS) in transit, and your data is encrypted at rest on Cloudflare's storage. Nothing moves or sits in the clear.

🔑

Passwordless sign-in

You sign in with a one-time code sent to your email — no password to be reused, phished, or leaked in a breach. Codes are single-use, expire in minutes, are rate-limited, and lock out after repeated wrong attempts.

🧠

We never train AI on your data

Your documents, entities, and generated work are used only to deliver your results. They are never used to train AI models — ours or any provider's. Zero-data-retention settings are enabled with our AI providers.

🏢

Per-firm isolation

Each firm's workspace is logically separated, and access is controlled by role (managing partner, corporate secretary, and equivalent tiers) with matter-level confidentiality and a full activity audit trail.

☁️

Enterprise-grade infrastructure

Your data is stored in Cloudflare's Asia-Pacific region (Singapore) and delivered over its global network — the same platform trusted by many of the world's largest companies — with DDoS protection, a web application firewall, and continuous monitoring.

💳

Payments handled by Stripe

Billing is processed by Stripe, a PCI-DSS Level 1 provider. We never see or store your card details.

📄

Your data stays yours

Export your work at any time. Records are archived rather than silently deleted, preserving a defensible audit trail — and we never sell your data.

🌍

Privacy, PDPA & GDPR

Our practices are aligned with PDPA and GDPR principles, and a Data Processing Agreement is available. Firms in the EU are served a dedicated Terms edition that includes a GDPR Data Processing Annex.

✍️

Electronic signatures & audit trail

Documents are signed electronically in a manner recognised under the Singapore Electronic Transactions Act 2010, the EU eIDAS Regulation (Article 25) and the US ESIGN Act and UETA. Each signature is recorded with the signer's name, method, time, IP address and device, and every executed copy carries an execution certificate with a SHA-256 document fingerprint.

What this means in practice
Certified infrastructure

GovernanceApp is hosted on Cloudflare, which maintains independent, audited security certifications — including SOC 2 Type II and ISO 27001 — so your firm's information sits on infrastructure that meets globally recognised security standards.

Supporting services come from carefully selected providers, including Stripe (PCI DSS Level 1) for payments, ILOVEPDF, S.L. (ISO/IEC 27001, GDPR-compliant; files are encrypted and automatically deleted within two hours) for document conversion, and AssemblyAI (SOC 2 Type 2, ISO/IEC 27001) for transcription. Sanctions screening is processed by OpenSanctions in Frankfurt, Germany.

The complete list of sub-processors, with the purpose and location of each, is published in our Terms of Service (Schedule 1) and, for EU firms, Appendix B.

Within that environment we apply the controls described above: access control, encryption in transit and at rest, least privilege, auditability, and secure development.

GovernanceApp Enterprise · Intellectus Universe Pte. Ltd.
Sign In  ·  Contact Sales
AI-assisted only — professional secretarial and governance review remains your responsibility.