Security
Service: AIGov
Website: https://govbase.dev
Operator: AIMLGov s.r.o., company ID 29742188
Registered office: Příčná 1892/4, Nové Město, 110 00 Praha 1, Czech Republic
General and privacy contact: hello@govbase.dev
Security contact: legal@govbase.dev
Version: 2026-09-30
Effective date: 2026-09-30
Last updated: 2026-09-30
About this page
This page summarizes the security measures that AIMLGov s.r.o. (“AIMLGov”, “we”, “us”) applies to the AIGov service at govbase.dev (the “Service”). It is a general, public-facing overview referenced from the Privacy Policy and Data Processing Addendum (DPA).
This page is not a contractual document. Where it differs from a finalized and applicable DPA, the DPA governs processing of Customer Data.
Infrastructure and hosting
AIGov uses established infrastructure providers rather than self-managed servers. The Service uses Vercel for application hosting, Railway for the audit API and PostgreSQL database, Cloudflare for network and DNS services, Stripe for billing, and Resend for transactional email.
The application is hosted in Vercel's iad1 region. Database connections use SSL/TLS. The current production vendor inventory and processing locations are maintained on the published Subprocessor List.
Encryption
Traffic to the Service uses HTTPS. Connections to the database use SSL/TLS.
Data stored on Railway is encrypted at the storage layer by Railway. Details of third-party controls remain subject to the applicable provider documentation and agreements.
Access control and tenant isolation
Requests to the audit API are scoped to a tenant through an API key verified and resolved by the backend. A tenant identifier supplied by a client is not treated as an authorization boundary.
Access to Customer Data within AIMLGov is limited to personnel who need it to operate and support the Service. Multi-factor authentication is required for team accounts with access to production infrastructure, including hosting, database, billing, and email services.
Certifications and assessments
AIMLGov s.r.o. does not hold SOC 2, ISO 27001, or FedRAMP certification. This page does not claim otherwise.
Third-party provider certifications or assessments do not certify AIMLGov's own practices.
We run automated dependency and security scans, including Trivy and gitleaks, in our development pipeline. As of this version, AIMLGov has not commissioned a third-party penetration test of the Service.
Vulnerability disclosure
If you believe you have found a vulnerability in the Service, please report it privately to legal@govbase.dev or follow the disclosure instructions in the repository's SECURITY.md file.
Please do not disclose an unpatched vulnerability publicly. We aim to acknowledge reports promptly and coordinate a reasonable disclosure timeline.
Incident response
We maintain an internal incident response process covering detection, containment, investigation, remediation, and customer notification. Contractual commitments concerning personal-data breaches are governed by a finalized and applicable DPA.
Data processing and subprocessors
The current Subprocessor List is published at https://govbase.dev/subprocessors and identifies the production providers, purposes, processing locations and transfer mechanisms currently disclosed by AIMLGov.
The DPA remains separately subject to finalization. Until a finalized DPA is validly incorporated or separately executed, this Security page does not create processor terms or replace a DPA.
Changes to this page
We may update this page when our infrastructure, security controls, vendors or certifications change. The version, effective date and last-updated date appear at the top of the page. Material changes will be reflected here.
Contact
For questions about this page, email hello@govbase.dev. To report a security concern, email legal@govbase.dev.
Postal correspondence may be addressed to AIMLGov s.r.o. at the registered office stated above.
Tenant-scoped acceptance is recorded only at /legal/acceptance after authentication — not on this page.