Trust Center

Documentation for security, procurement, and compliance reviewers evaluating AI Governance Hub.

Security architecture

AI Governance Hub follows a fail-closed security model. Payment verification, work item counting, plan detection, and report generation run exclusively on the server. The browser never authorizes downloads or sets commercial terms.

Full Security Policy · Technical security documentation

Security review package (for CISO & security architects)

Documents available today for vendor review — we do not claim certifications we have not earned.

Available for download / review

Sub-processors

  • Razorpay — payment processing (PCI handled by Razorpay; we do not store card/UPI data)
  • Vercel — serverless API, static site delivery, and encrypted Blob object storage for generated reports (TLS, HSTS in production; United States region by default)
  • Zoho — transactional email delivery (report links, sign-in links, receipts)
  • Google LLC — Google Analytics 4 usage analytics only, subject to your consent where required; advertising features permanently disabled (see Privacy Policy)
  • Atlassian Forge — Marketplace app runs inside your own Jira Cloud tenant with no data egress (separate from website uploads)

For sub-processor questionnaires or custom DPAs, contact security@aigovernancehub.ai.

What we do not claim

  • SOC 2 Type II, ISO 27001 certification, or FedRAMP authorization (unless separately contracted and documented)
  • HIPAA BAA or banking regulatory approval through software alone
  • That a report constitutes legal certification or regulatory sign-off

Data residency

Website assessment: uploads and generated reports are processed and stored on Vercel infrastructure in the United States (default serverless region). Upload sessions expire within ~24 hours; reports are recoverable for 90 days unless earlier deletion is requested.

Marketplace app (recommended for production and sensitive data): governance data stays inside your own Atlassian Cloud tenant and region via Atlassian Forge. The app has no external egress — data never leaves Atlassian. For region-specific residency requirements on the website flow, contact security@aigovernancehub.ai.

Deployment scale (honest limits)

Website assessment Self-serve up to 1,000 work items per upload. Single purchaser email per assessment. Not multi-tenant SSO on this flow.
Enterprise assessment (1,001+ items) Sales-scoped quote, secure payment link, dedicated handling. Contact sales@aigovernancehub.ai.
Production Jira teams (100–5,000+ users) Atlassian Marketplace app with Forge tenant isolation — the path for ongoing governance workflows, not the website upload flow.
Global deployment Website assessments are server-processed; production governance runs in your Atlassian cloud region via Marketplace install.

Regulated industry buyers

Industry selection during upload adjusts report framing — it does not create compliance certification.

Handling sensitive or regulated data? Use the in-tenant path. The Atlassian Marketplace app processes governance data entirely inside your own Atlassian Cloud tenant with no data egress — the recommended path for PHI, PII, or confidential portfolios. The website assessment flow is intended for evaluation using redacted or synthetic exports.

Customer responsibility: You control what leaves your environment. We process what you upload solely to deliver your assessment.

Assessment data & AI processing

Website assessment uploads are processed on our servers solely to generate your governance report and deliver it to you. We do not use your upload to train third-party AI models. Analysis uses governance-weighted rules and portfolio metrics — not public redistribution of your export.

Deletion requests: support@aigovernancehub.ai

Support SLAs

Confidential upload handling

Assessment uploads may contain sensitive project metadata. We treat every upload accordingly:

Deletion requests: support@aigovernancehub.ai

Privacy

We process uploaded project data solely to generate your assessment and deliver reports. Payment details are handled exclusively by Razorpay.

Privacy Policy · Cookie Policy

Infrastructure

Persistent encrypted object storage, serverless API routes, and environment-isolated secrets. Production Jira governance workflows run on Atlassian Forge within your tenant boundary.

Encryption

Payment integrity

Order amounts are calculated server-side from detected plan and portfolio size. The total shown in your order summary must match the Razorpay checkout amount exactly. Reports generate only after cryptographic payment verification.

Refund Policy

Data lifecycle & retention

Upload → validation → analysis → verified payment → report generation → secure delivery → dashboard recovery. Upload sessions expire. Recovery tokens remain valid for 90 days unless deletion is requested.

Customer & vendor responsibilities

Your responsibilities: Ensure uploads comply with internal data policies; provide accurate contact details; retain payment references for support.

Our responsibilities: Secure processing, server-side validation, verified payment before delivery, audit logging, and timely support response per published SLAs.

Compliance posture

Framework mapping supports EU AI Act, ISO 42001, and NIST AI RMF evidence workflows. Reports assist governance review and board reporting — they do not constitute legal certification or regulatory approval.

Contact

Security: security@aigovernancehub.ai
Support: support@aigovernancehub.ai
Enterprise sales: sales@aigovernancehub.ai

Frequently asked questions

Next step

Reviewed what you need?

Start a free governance preview — no card required — or install the Forge app to keep all data in your Atlassian tenant.