Skip to content

Security

Last updated: May 2026

This document summarizes the security practices and controls GovSynth applies to the platform. It supplements the Terms of Service, Privacy Policy, and Data Processing Addendum.

Identity & Access

  • SSO via Customer Provided Microsoft Entra ID
  • RBAC enforced at tenant level
  • Privileged roles restricted and logged

Data Protection

  • Encryption in transit and at rest
  • Key management via Azure platform and Key Vault

Logging & Monitoring

  • Centralized logging via Application Insights
  • Audit logging for all mutating actions
  • Structured telemetry for system behavior

Secure Development

  • SAST via CodeQL on all PRs
  • Dependency scanning via Dependabot
  • High-severity issues resolved before release

Change Management

  • All changes require PR, review, and approval
  • Infrastructure defined via IaC

Vulnerability Management

  • Continuous scanning and patching
  • Critical issues remediated prior to deployment

Incident Response

  • Detection via logging and monitoring tools
  • Response processes defined in separate policy

Operational Security

  • Platform updates managed via Azure
  • Secrets stored and managed via Key Vault

Audit & Assurance

  • Security documentation available upon request
  • Customer audits subject to reasonable limits