Where your data lives, and what we do with it
Plain answers, not a compliance-marketing page. If something here matters to your own security review, ask us directly: contact sales.
The short version
GovernedAI is built to exclude protected health information (PHI). We do not offer a Business Associate Agreement (BAA) today, and we do not claim HIPAA compliance or any security certification. If your organization needs to put PHI into a system, GovernedAI is not the right place for it yet. See below for what that means in practice.
What GovernedAI is designed to hold
GovernedAI is a system of record for your AI governance program, not for the data your AI systems themselves process. What you put into GovernedAI is metadata about your AI systems and your governance activity around them:
- AI system names, owners, business units, deployment status, and risk classifications
- Vendor names, contacts, BAA/SOC 2 status, and evidence you attach (documents, links)
- Workflow decisions, rationale, and the audit trail of who did what and when
- Incident reports, remediation notes, and reassessment records
- User accounts for people at your organization who use GovernedAI
None of that is designed to be patient-level clinical data. Free-text fields (descriptions, notes, incident write-ups) and uploaded evidence files are the places PHI could end up if someone pastes or uploads it. Please don’t. Our Terms prohibit putting PHI into the product, and we’ll ask you to remove it if we become aware it’s there.
Where it's hosted
GovernedAI runs on mainstream, widely used cloud infrastructure with a managed database. Evidence files you upload are stored separately from the database, in isolated object storage, with access checked on every download. We chose our infrastructure providers for reliability and speed of iteration, not because they're certified for PHI in our current setup.
Access & isolation
- Each customer is its own organization with strict data isolation; no organization can see another’s data.
- Role-based access control: admins, reviewers, and contributors see and can do different things.
- Single sign-on (SAML/OIDC) is available on Growth and Enterprise plans.
- An audit log records who did what, when, on every AI system.
- API access uses per-organization keys, scoped to that organization’s data only.
If you need a BAA
We don’t offer one today. If a BAA becomes a real requirement for your organization, talk to us; it’s something we plan for, not something we’ve ruled out, but it is not available on any plan right now, including Enterprise.
Questions we didn’t answer here?
Send us your security questionnaire, or just ask.