Is this your company? Buyers are checking GovAI here. Claim govai.com free to control the listing, earn the badge buyers trust, and see who's evaluating you.
Claim free
GovAI
Sourced from public information. Not yet verified by the company.
GovAI is SOC 2 Type II compliant. GovAI also holds NIST CSF.
About
GovAI is SOC 2 Type II compliant and committed to providing full transparency to our users via our Trust Center. You can see a real-time view of the controls and policies we have in place which are continuously monitored to ensure the platform remains safe and secure.
Compliance & infrastructure
Documents
4Subprocessors
6- AAmazon Web Services · Cloud provider
- OOh Dear · Application Monitoring
- VVanta · Security
- MMixpanel · Application Analytics
- IIntercom · Customer support
- OOpenAI · LLM Provider
Compliance leadership
The person who leads GovAI's SOC 2 isn't listed yet. Claim this profile to add it.
Penetration test
Unknown. GovAI's penetration test vendor isn't listed yet.
Claim this profile to add it.
Recent updates
GovAI Completes Annual PentestMay 2026
GovAI engaged Valorin Security Pty Ltd to conduct a focused Laravel Security Audit and Penetration Test. The audit was conducted over a 2 week period from 6th April 2026 through to 17th April 2025 and included a comprehensive review of the Laravel application source code, and a penetration test conducted on a dedicated staging instance, made available for the duration of the audit. "Overall the application security of GovAI is at a high level, with secure coding patterns in use throughout the code. Although some issues were discovered, they were resolved promptly and indicate minor coding mistakes or incomplete implementations, rather than insecure patterns or signs of larger problems." - Stephen Rees-Carter, valorinsecurity.com, CompTIA Security+ & Certified Ethical Hacker
GovAI Renews SOC 2 Type IINov 2025
This renewal indicates that our handling and processing of customers’ data meets key security standards. The protection of customer data is the highest priority for our team and we’re committed to building a robust security & compliance program. We’re thrilled to celebrate this milestone as another way of building trust with our customers. We partnered with Vanta & Advantage Partners to seamlessly guide us through the compliance process. You can now view our SOC 2 report in our Trust Center. Please let us know if you have any questions.
GovAI Completes Annual PentestJun 2025
GovAI engaged Valorin Security Pty Ltd to conduct a focused Laravel Security Audit and Penetration Test. The audit was conducted over a 2 week period from 19th May 2025 through to 3rd June 2025 and included a comprehensive review of the Laravel application source code, and a penetration test conducted on a dedicated staging instance, made available for the duration of the audit. "Overall the application security of GovAI is at a high level, with secure coding patterns in use throughout the code. Although some issues were discovered, they were resolved promptly and indicate minor coding mistakes or incomplete implementations, rather than insecure patterns or signs of larger problems." - Stephen Rees-Carter, valorinsecurity.com, CompTIA Security+ & Certified Ethical Hacker
GovAI Achieves SOC 2 Type IIOct 2024
This achievement indicates that our handling and processing of customers’ data meets key security standards. The protection of customer data is the highest priority for our team and we’re committed to building a robust security & compliance program. We’re thrilled to celebrate this milestone as another way of building trust with our customers. We partnered with Vanta & Advantage Partners to seamlessly guide us through the compliance process. You can now view our SOC 2 report in our Trust Center. Please let us know if you have any questions.
This listing is partial
7/11 details · 64%SOC2C shows the verified essentials. 4 details are not yet provided by the company. Trust centers list more, so we invite the owner to fill the gaps here.
- Auditorraises trustAdd the CPA firm that issued your SOC 2 so buyers can verify who signed it.
- Report dateraises trustAdd your most recent report period so buyers see how current your SOC 2 is.
- Renewal dateAdd your renewal window so buyers know your coverage is active.
- Security controlsConfirm key controls (encryption, MFA/SSO, annual pen test, BCP/DR) buyers screen for.
Verify your work email to take ownership, earn the badge buyers trust, and add the details that win deals.
Frequently asked
Is GovAI SOC 2 compliant?
Is GovAI NIST CSF compliant?
Is GovAI SOC 2 Type I or Type II?
Can I use GovAI's SOC 2 for a vendor risk assessment?
Is GovAI penetration tested?
Can I get GovAI's SOC 2 report?
Is GovAI secure?
Does GovAI have a bug bounty or vulnerability disclosure program?
Who are GovAI's subprocessors?
Where does GovAI host or store data?
Where is GovAI's trust center or security page?
Do you encrypt data at rest?
How does GovAI encrypt data in-transit?
Do the cryptographic module used for encryption meet FIPS 140-2 standards?
Do you support Single Sign-On (SSO)?
What are your Recovery Time Objective (RTO) and Recovery Point Objectives (RPO)?
Does the platform meet the requirements for web accessibility?
What governance frameworks does GovAI use for development of AI?
Technology peers that completed SOC 2

Action1

ELJUN LLC

equipifi
