GovernanceApp is built for company secretaries, corporate-services firms and in-house governance teams. Your entities, statutory registers, board records, and client information are among the most confidential data your firm holds — here is how we protect them.
All traffic is protected with TLS (HTTPS) in transit, and your data is encrypted at rest on Cloudflare's storage. Nothing moves or sits in the clear.
You sign in with a one-time code sent to your email — no password to be reused, phished, or leaked in a breach. Codes are single-use, expire in minutes, are rate-limited, and lock out after repeated wrong attempts.
Your documents, entities, and generated work are used only to deliver your results. They are never used to train AI models — ours or any provider's. Zero-data-retention settings are enabled with our AI providers.
Each firm's workspace is logically separated, and access is controlled by role (managing partner, corporate secretary, and equivalent tiers) with matter-level confidentiality and a full activity audit trail.
Your data is stored in Cloudflare's Asia-Pacific region (Singapore) and delivered over its global network — the same platform trusted by many of the world's largest companies — with DDoS protection, a web application firewall, and continuous monitoring.
Billing is processed by Stripe, a PCI-DSS Level 1 provider. We never see or store your card details.
Export your work at any time. Records are archived rather than silently deleted, preserving a defensible audit trail — and we never sell your data.
Our practices are aligned with PDPA and GDPR principles, and a Data Processing Agreement is available. Firms in the EU are served a dedicated Terms edition that includes a GDPR Data Processing Annex.
Documents are signed electronically in a manner recognised under the Singapore Electronic Transactions Act 2010, the EU eIDAS Regulation (Article 25) and the US ESIGN Act and UETA. Each signature is recorded with the signer's name, method, time, IP address and device, and every executed copy carries an execution certificate with a SHA-256 document fingerprint.
GovernanceApp is hosted on Cloudflare, which maintains independent, audited security certifications — including SOC 2 Type II and ISO 27001 — so your firm's information sits on infrastructure that meets globally recognised security standards.
Supporting services come from carefully selected providers, including Stripe (PCI DSS Level 1) for payments, ILOVEPDF, S.L. (ISO/IEC 27001, GDPR-compliant; files are encrypted and automatically deleted within two hours) for document conversion, and AssemblyAI (SOC 2 Type 2, ISO/IEC 27001) for transcription. Sanctions screening is processed by OpenSanctions in Frankfurt, Germany.
The complete list of sub-processors, with the purpose and location of each, is published in our Terms of Service (Schedule 1) and, for EU firms, Appendix B.
Within that environment we apply the controls described above: access control, encryption in transit and at rest, least privilege, auditability, and secure development.