Security and data protection
Last updated 23 August 2026
Governance Row holds the AI-governance records a regulated firm relies on at inspection. This page states how those records are hosted, encrypted, and protected. It reflects current practice for the founding-cohort release and will expand as the platform matures.
Hosting and data residency
Customer data is hosted on Supabase in the ap-southeast-1 (Singapore) region. Company registration in Singapore and data residency in Singapore are stated separately and both hold.
Tenancy
The platform is multi-tenant. Tenant isolation is enforced by row-level security (RLS) at the database layer, so one firm cannot read or write another firm's records.
Encryption
Data is encrypted at rest with AES-256 (via Supabase) and in transit with TLS 1.2 or higher.
Authentication
Multi-factor authentication is required for all accounts, using time-based one-time passwords (TOTP).
Audit trail
Every change is written to an immutable, append-only audit trail server-side. Records cannot be edited or deleted through the application.
Sub-processors
- Supabase, database and authentication (Singapore region).
- Vercel, application hosting.
- Resend, transactional email delivery.
Incident response
We commit to notifying affected customers within 72 hours of confirming a security incident.
Data portability
You can request a full export of your data at any time. Exports are delivered within 5 business days, under our Data Export and Exit Guarantee.
Certifications roadmap
- Cyber Essentials, targeted H2 2026.
- SOC 2 Type I, targeted Year 2.
- ISO 27001, targeted Year 2 and beyond.
Certifications listed under the roadmap are targets, not current attestations.
A detailed security and compliance pack, including our data processing agreement, is available to prospective customers on request.
Reach the team at hello@governancerow.com for the current security posture. Data protection queries: dpo@governancerow.com.