Trust & security

Govern AI tools without monitoring your people.

GovernKit stores the records your team creates: requests, policies, approvals, and audit events.

GovernKit never watches your people.

There are no browser extensions, no traffic inspection, no prompt logs. We read the vendor's public documents and record your team's decisions. That's the whole footprint.

No cookiesNo trackersNo prompt monitoring

How we protect your account and records

Encrypted in transit and at rest

Traffic is encrypted with TLS, product data sits in managed Postgres with encryption at rest, and backups expire within 30 days.

Two-factor authentication

Every user can turn on 2FA with QR setup and backup codes.

Isolated teams

Each team has its own members, tools, policies, and billing, and team data stays separate.

Role-based access

Owner, admin, manager, and member roles are built in, and sensitive actions are permission-checked.

Payments by Stripe

Card details go to Stripe, never to our servers.

A complete audit trail

Every meaningful event lands in a chronological, filterable audit log.

Honest limits

Pricing cards show the same limits the product enforces.

Your data, your exit

Export your personal data or whole workspace anytime, and delete your account without a support ticket.

GDPR compliant

GDPR compliant. Your data stays yours.

See, export, or erase your data from your own settings. The details are spelled out in our Privacy Policy and Data Processing Addendum.

Export everything, anytimeDownload your personal data as JSON, or your whole workspace as a ZIP, directly from settings.
Delete your account instantlyImmediate, self-serve erasure with your audit entries anonymized. No waiting period.
A DPA with EU Standard Contractual ClausesCovers every workspace, with documented subprocessors and breach notification.
Data that expires on scheduleFixed retention windows for sessions, invitations, AI usage records, and backups.

What we deliberately don't collect

The safest data is data we never hold.

We store
  • Tool names, vendors, and categories
  • Request descriptions and decisions
  • Policies, versions, and acknowledgements
  • Names, emails, roles, and audit events
We never touch
  • Prompts or AI conversation content
  • Your files or confidential documents
  • Browsing activity or screen data
  • Anything requiring agents or extensions
Security questions? Ask a human.

We can walk you through our practices or help with your vendor questionnaire.

Contact us