Governance Row
SECURITY

Security and data protection

Last updated 23 August 2026

Governance Row holds the AI-governance records a regulated firm relies on at inspection. This page states how those records are hosted, encrypted, and protected. It reflects current practice for the founding-cohort release and will expand as the platform matures.

Hosting and data residency

Customer data is hosted on Supabase in the ap-southeast-1 (Singapore) region. Company registration in Singapore and data residency in Singapore are stated separately and both hold.

Tenancy

The platform is multi-tenant. Tenant isolation is enforced by row-level security (RLS) at the database layer, so one firm cannot read or write another firm's records.

Encryption

Data is encrypted at rest with AES-256 (via Supabase) and in transit with TLS 1.2 or higher.

Authentication

Multi-factor authentication is required for all accounts, using time-based one-time passwords (TOTP).

Audit trail

Every change is written to an immutable, append-only audit trail server-side. Records cannot be edited or deleted through the application.

Sub-processors

  • Supabase, database and authentication (Singapore region).
  • Vercel, application hosting.
  • Resend, transactional email delivery.

Incident response

We commit to notifying affected customers within 72 hours of confirming a security incident.

Data portability

You can request a full export of your data at any time. Exports are delivered within 5 business days, under our Data Export and Exit Guarantee.

Certifications roadmap

  • Cyber Essentials, targeted H2 2026.
  • SOC 2 Type I, targeted Year 2.
  • ISO 27001, targeted Year 2 and beyond.

Certifications listed under the roadmap are targets, not current attestations.

A detailed security and compliance pack, including our data processing agreement, is available to prospective customers on request.

Reach the team at hello@governancerow.com for the current security posture. Data protection queries: dpo@governancerow.com.