Where you go before you sign anything.
Security, privacy, terms, data-processing addendum, status, and the responsible-disclosure path: collected on one page so procurement and security review never has to triage tabs.
Security
Encryption, access control, the team that owns response, and how we engineer for least-privilege end-to-end.
Privacy
What we collect, why, how long we keep it, and how we honor data-subject requests. GDPR + CCPA + state-equivalent.
Terms of service
Subscription terms, acceptable use, IP, indemnification, and dispute resolution. Plain-language drafted, counsel-reviewed.
Data Processing Addendum
Pre-signed DPA for GDPR + CCPA, including SCC for EU data transfer. Add the appendices and counter-sign.
Status page
Component-level uptime, incident timeline, and post-mortems for customer-affecting events.
Responsible disclosure
Coordinated-disclosure path with safe-harbor language. Email security@trygovbidai.com with reproducible findings.
Status & incident log
Component-level uptime, incident timeline, and post-mortems are published on our live status page. Customer-affecting incidents are posted within 15 minutes of confirmation; root-cause write-ups are published after each Severity-1 event.
Subscribe at the status page to receive email or webhook alerts on any state change.
Status data is published from our live monitoring; this card reflects the current state at page-load time. Historical incidents and uptime data live on the status page.
Every vendor with access to customer data, listed.
We notify customers 30 days before adding any new subprocessor. The current list, with each vendor's purpose and data-residency region:
| Vendor | Purpose | Region |
|---|---|---|
| Supabase | Database, auth, storage | US |
| Railway | Application hosting | US |
| Cloudflare | CDN, DNS, edge functions | Global, US POPs |
| Stripe | Billing & subscriptions | US |
| Anthropic | LLM inference for product features | US |
| SendGrid | Transactional email | US |
| PostHog | Product analytics | US |
| Sentry | Error monitoring | US |
Where your data lives.
Customer data is stored in the United States. Our database, hosting, edge, and analytics subprocessors all operate in US regions. EU and dedicated regional tenancy are on the roadmap; we will notify customers when they are generally available.
Contact us about residency requirements →If you find something, tell us. We credit, we patch, we follow up.
We welcome coordinated disclosure of security issues. Email the address at right with a clear repro and your preferred credit. We will acknowledge receipt and keep you posted as we work the fix.