Security & compliance
Built for the standard your reviewers apply.
Controls mapped to NIST SP 800-53, cryptography designed to FIPS 140-3 on validated modules, and data residency in the United States and Canada.
Security review is a substantive stage in government procurement. This page gives the GovCore position with the precision that a review needs.
01Certification
Certification and assurance
The cloud platforms that GovCore runs on hold SOC 2 and ISO 27001. GovCore implements its own control families and maps them to NIST SP 800-53. The certified payment processors handle payment cards.
02Residency
Data stays in its country of origin
GovCore stores regulatory data in the country it came from. Residency is available in the United States, on FedRAMP-authorized cloud infrastructure, and in Canada. The data does not leave the region that an agency selects.
03Isolation
Separation between agencies
GovCore isolates each agency's data at the storage layer.
04Access
Sign-in that fits your identity provider
Single sign-on via SAML 2.0, multi-factor authentication, role-based access control, and scoped tokens and service accounts for system access.
05Sessions
Session governance
Inactivity timeouts, session revocation and token rotation. A reviewable record shows active and past sessions.
06Uploads
Malware scanning on every upload
GovCore scans every file that arrives from the public. It releases the file only after a clean result. Every regulator with a public portal carries this attack surface.
07Audit
Audit trails throughout
Change history on records, an outbound email audit, a session audit, and an audit of AI activity. A decision stays defensible on later review.
08Uptime
99.9% uptime
GovCore runs at 99.9% uptime. This is performance we have achieved. It is not a level we promise in a contract. A public status board shows current service.
09Encryption
Encryption and hardening
Encryption at rest and in transit, with managed key envelope encryption. Application-layer hardening adds request forgery protection, rate limiting, security headers and strict host validation.
10Cryptography
Cryptography designed to FIPS 140-3
GovCore encrypts data at rest and in transit with FIPS 140-validated cryptographic modules. The GovCore cryptographic design follows FIPS 140-3.
NIST SP 800-53
All 20 control families, and where each one sits.
GovCore’s controls are mapped to the twenty control families of NIST SP 800-53 Rev 5. The map below sets out how each family is addressed, and where responsibility sits between GovCore and the cloud platform.
GovCore operates the families marked GovCore. Shared families are carried partly by GovCore and partly by the cloud platform. Inherited families belong to the cloud platform.
ACAccess Control
Role-based access with least-privilege roles. Single sign-on through SAML 2.0. Scoped tokens and service accounts for system access. GovCore enforces tenant isolation at the storage layer.
GovCoreATAwareness and Training
GovCore assigns security responsibilities by role. Staff receive training for the access they hold. They receive that training before GovCore grants the access.
GovCoreAUAudit and Accountability
Change history on every record, an audit of outbound correspondence, session audit and an audit of AI activity. Audit records are exportable and retained so a decision remains explainable years later.
GovCoreCAAssessment, Authorization and Monitoring
Continuous monitoring and vulnerability scanning run against the platform, with controls reviewed and mapped to this catalogue. The cloud platforms carry their own independent audits.
SharedCMConfiguration Management
GovCore holds agency configuration as data, with a full change history. Application changes move through version control, review and separated environments before they reach production.
GovCoreCPContingency Planning
Incremental backups and point-in-time recovery within a configurable window of one to thirty-five days, with recovery procedures exercised rather than assumed.
SharedIAIdentification and Authentication
Multi-factor authentication, single sign-on against the agency’s own identity provider, password policy, inactivity timeout, session revocation and token rotation.
GovCoreIRIncident Response
A defined incident response procedure with assigned ownership, severity classification and agency notification. The cloud platform provides infrastructure-level detection.
SharedMAMaintenance
GovCore schedules and performs platform maintenance. The cloud platform maintains the physical infrastructure.
SharedMPMedia Protection
The cloud platform manages, sanitizes and disposes of storage media. GovCore holds no physical media. GovCore encrypts data before it reaches storage.
InheritedPEPhysical and Environmental Protection
Data-centre physical security, power, fire suppression and environmental controls belong to the cloud platform. GovCore operates no facility of its own that holds regulatory data.
InheritedPLPlanning
GovCore documents the security architecture, the data flows and the rules of behaviour. It reviews them as the platform changes, not at a fixed interval.
GovCorePMProgram Management
Named ownership for the security programme, a maintained risk register, and periodic review of controls against this catalogue.
GovCorePSPersonnel Security
All roles require a background check, as applicable law permits. Confidentiality terms are a condition of employment. GovCore revokes access on departure or on a change of role.
GovCorePTPII Processing and Transparency
GovCore collects personal information for a stated purpose and uses it for no other. The privacy policy sets out what GovCore holds, and why. GovCore minimizes applicant data by design. It never uses that data to classify a candidate.
GovCoreRARisk Assessment
Vulnerability scanning, dependency monitoring and static analysis run against the codebase, with findings triaged by severity rather than by convenience.
GovCoreSASystem and Services Acquisition
A secure development lifecycle: code review, static analysis in the pipeline, dependency review before adoption, and separated development, staging and production environments.
GovCoreSCSystem and Communications Protection
Encryption in transit and at rest, with managed key envelope encryption. Tenant isolation at the storage layer. Request forgery protection, rate limiting, security headers and strict host validation. GovCore designs its cryptography to FIPS 140-3, on the cloud platform’s validated modules.
SharedSISystem and Information Integrity
GovCore scans every uploaded file for malware before it releases the file. It sanitizes all untrusted HTML on the server. It validates every submission on the server, whatever the client checked. It monitors the platform and patches on a defined cadence.
GovCoreSRSupply Chain Risk Management
A maintained inventory of third-party dependencies, monitored against published advisories, with updates assessed on severity.
GovCore
The rest of the platform
Licensing & renewals
Guided applications, assessment, issuance and renewal on one record.
Read moreCompliance & education
The system enforces continuing-education rules, delivers examinations, and tracks certification currency.
Read moreComplaints & enforcement
Intake, investigation, response and decision — one case, one record, one history.
Read moreBoard & committee
Committees, members, meetings and materials held in the system of record.
Read morePublic & licensee portals
Verification, applications, renewals, payments and records requests, without a call to your office.
Read morePayments & revenue
Integrated payments in both the staff workspace and the public portals.
Read moreCorrespondence
Email, SMS, secure messaging and generated letters — logged, templated and audited.
Read moreReporting & insight
Report builders, dashboards and exports over live regulatory data.
Read moreAI for regulators
Assistance, triage and drafting: governed, auditable, and enabled only where the agency chooses.
Read moreConfiguration & integration
An agency defines record types, forms, views, workflow and navigation as configuration.
Read moreDemonstrations
See the platform against your own requirements.
We provide demonstrations to government agencies at no cost. They create no obligation. We work through your own licence types, workflows and reporting requirements, not a generic configuration.