Skip to main content
Govly treats privacy and security as core parts of operating the platform. This page summarizes our approach to safeguarding data and supporting privacy requirements.

Security Program

Govly maintains a security and privacy program covering access management, secure development, vulnerability management, incident response, vendor management, and workforce training. Govly has completed a SOC 2 Type I examination and is preparing to enter a SOC 2 Type II observation period in August 2026. Contact support@govly.com for current independent assessment reports and their scope.

The Data in Scope

Govly processes public procurement data and customer-provided account and workflow content needed to deliver the service. Customers control the users and content in their organizations. Govly does not sell or rent customer-provided information.

Infrastructure

Govly uses AWS-hosted infrastructure in United States regions. Safeguards include network segmentation, access controls, multi-factor authentication for administrative access, patching, vulnerability scanning, logging, and threat detection. AWS compliance programs apply to AWS services and do not by themselves certify Govly.

Network and Data Encryption

Govly uses TLS for data in transit and encryption at rest for production data.

Product Security

Administrators manage user access for their Govly organization. Govly also supports SAML-based single sign-on. Govly separately identifies and manages restricted opportunity attachments, including customer-configurable access controls and automatic retention for eligible files.