Monthly demonstration · August 20

Security & compliance

Built for the standard your reviewers apply.

Controls mapped to NIST SP 800-53, cryptography designed to FIPS 140-3 on validated modules, and data residency in the United States and Canada.

All capabilities

Security review is a substantive stage in government procurement. This page gives the GovCore position with the precision that a review needs.

  1. 01Certification

    Certification and assurance

    The cloud platforms that GovCore runs on hold SOC 2 and ISO 27001. GovCore implements its own control families and maps them to NIST SP 800-53. The certified payment processors handle payment cards.

  2. 02Residency

    Data stays in its country of origin

    GovCore stores regulatory data in the country it came from. Residency is available in the United States, on FedRAMP-authorized cloud infrastructure, and in Canada. The data does not leave the region that an agency selects.

  3. 03Isolation

    Separation between agencies

    GovCore isolates each agency's data at the storage layer.

  4. 04Access

    Sign-in that fits your identity provider

    Single sign-on via SAML 2.0, multi-factor authentication, role-based access control, and scoped tokens and service accounts for system access.

  5. 05Sessions

    Session governance

    Inactivity timeouts, session revocation and token rotation. A reviewable record shows active and past sessions.

  6. 06Uploads

    Malware scanning on every upload

    GovCore scans every file that arrives from the public. It releases the file only after a clean result. Every regulator with a public portal carries this attack surface.

  7. 07Audit

    Audit trails throughout

    Change history on records, an outbound email audit, a session audit, and an audit of AI activity. A decision stays defensible on later review.

  8. 08Uptime

    99.9% uptime

    GovCore runs at 99.9% uptime. This is performance we have achieved. It is not a level we promise in a contract. A public status board shows current service.

  9. 09Encryption

    Encryption and hardening

    Encryption at rest and in transit, with managed key envelope encryption. Application-layer hardening adds request forgery protection, rate limiting, security headers and strict host validation.

  10. 10Cryptography

    Cryptography designed to FIPS 140-3

    GovCore encrypts data at rest and in transit with FIPS 140-validated cryptographic modules. The GovCore cryptographic design follows FIPS 140-3.

NIST SP 800-53

All 20 control families, and where each one sits.

GovCore’s controls are mapped to the twenty control families of NIST SP 800-53 Rev 5. The map below sets out how each family is addressed, and where responsibility sits between GovCore and the cloud platform.

GovCore operates the families marked GovCore. Shared families are carried partly by GovCore and partly by the cloud platform. Inherited families belong to the cloud platform.

  1. ACAccess Control

    Role-based access with least-privilege roles. Single sign-on through SAML 2.0. Scoped tokens and service accounts for system access. GovCore enforces tenant isolation at the storage layer.

    GovCore
  2. ATAwareness and Training

    GovCore assigns security responsibilities by role. Staff receive training for the access they hold. They receive that training before GovCore grants the access.

    GovCore
  3. AUAudit and Accountability

    Change history on every record, an audit of outbound correspondence, session audit and an audit of AI activity. Audit records are exportable and retained so a decision remains explainable years later.

    GovCore
  4. CAAssessment, Authorization and Monitoring

    Continuous monitoring and vulnerability scanning run against the platform, with controls reviewed and mapped to this catalogue. The cloud platforms carry their own independent audits.

    Shared
  5. CMConfiguration Management

    GovCore holds agency configuration as data, with a full change history. Application changes move through version control, review and separated environments before they reach production.

    GovCore
  6. CPContingency Planning

    Incremental backups and point-in-time recovery within a configurable window of one to thirty-five days, with recovery procedures exercised rather than assumed.

    Shared
  7. IAIdentification and Authentication

    Multi-factor authentication, single sign-on against the agency’s own identity provider, password policy, inactivity timeout, session revocation and token rotation.

    GovCore
  8. IRIncident Response

    A defined incident response procedure with assigned ownership, severity classification and agency notification. The cloud platform provides infrastructure-level detection.

    Shared
  9. MAMaintenance

    GovCore schedules and performs platform maintenance. The cloud platform maintains the physical infrastructure.

    Shared
  10. MPMedia Protection

    The cloud platform manages, sanitizes and disposes of storage media. GovCore holds no physical media. GovCore encrypts data before it reaches storage.

    Inherited
  11. PEPhysical and Environmental Protection

    Data-centre physical security, power, fire suppression and environmental controls belong to the cloud platform. GovCore operates no facility of its own that holds regulatory data.

    Inherited
  12. PLPlanning

    GovCore documents the security architecture, the data flows and the rules of behaviour. It reviews them as the platform changes, not at a fixed interval.

    GovCore
  13. PMProgram Management

    Named ownership for the security programme, a maintained risk register, and periodic review of controls against this catalogue.

    GovCore
  14. PSPersonnel Security

    All roles require a background check, as applicable law permits. Confidentiality terms are a condition of employment. GovCore revokes access on departure or on a change of role.

    GovCore
  15. PTPII Processing and Transparency

    GovCore collects personal information for a stated purpose and uses it for no other. The privacy policy sets out what GovCore holds, and why. GovCore minimizes applicant data by design. It never uses that data to classify a candidate.

    GovCore
  16. RARisk Assessment

    Vulnerability scanning, dependency monitoring and static analysis run against the codebase, with findings triaged by severity rather than by convenience.

    GovCore
  17. SASystem and Services Acquisition

    A secure development lifecycle: code review, static analysis in the pipeline, dependency review before adoption, and separated development, staging and production environments.

    GovCore
  18. SCSystem and Communications Protection

    Encryption in transit and at rest, with managed key envelope encryption. Tenant isolation at the storage layer. Request forgery protection, rate limiting, security headers and strict host validation. GovCore designs its cryptography to FIPS 140-3, on the cloud platform’s validated modules.

    Shared
  19. SISystem and Information Integrity

    GovCore scans every uploaded file for malware before it releases the file. It sanitizes all untrusted HTML on the server. It validates every submission on the server, whatever the client checked. It monitors the platform and patches on a defined cadence.

    GovCore
  20. SRSupply Chain Risk Management

    A maintained inventory of third-party dependencies, monitored against published advisories, with updates assessed on severity.

    GovCore

Demonstrations

See the platform against your own requirements.

We provide demonstrations to government agencies at no cost. They create no obligation. We work through your own licence types, workflows and reporting requirements, not a generic configuration.