Security & Governance

Enterprise-grade security for sensitive commercial data

GovernTerms and PayRight are designed for use with sensitive public sector commercial data. Security, compliance and governance are built into the platform, not bolted on.

Security principles

Data security

All data is encrypted in transit and at rest. Access is controlled by role-based permissions and multi-factor authentication. We do not share client data with third parties.

UK data residency

Client data is stored and processed within the United Kingdom. We do not transfer data outside the UK without explicit client consent.

Audit trail

Every analysis, finding and resolution is logged with a full, immutable audit trail, supporting internal governance, external audit and regulatory compliance requirements.

Access controls

Role-based access controls ensure that users only see the data relevant to their role. All access is logged and reviewable.

Compliance

GovernTerms operates in accordance with UK GDPR and the Data Protection Act 2018. We maintain appropriate technical and organisational measures to protect personal and commercial data.

Incident response

We maintain a documented incident response process. In the event of a security incident affecting client data, we will notify affected clients promptly and in accordance with our legal obligations.

Accreditations & certifications

Cyber Essentials Certified

Cyber Essentials Certified

The UK government-backed scheme demonstrating our commitment to protecting client data against the most prevalent cyber threats.

HM Government G-Cloud 15 Supplier

G-Cloud 15 Supplier

GovernTerms is an approved supplier on the HM Government G-Cloud 15 framework, enabling public sector organisations to procure our services directly through the Crown Commercial Service Digital Marketplace.

Governance framework

Our governance framework covers data handling, access management, incident response and business continuity. We review and update our policies regularly and make documentation available to clients on request.

UK GDPR and Data Protection Act 2018
UK data residency with no international transfers without consent
Encryption in transit and at rest
Role-based access controls with full access logging
Immutable audit trail for all platform activity
Documented incident response and business continuity

Questions about security?

If you have specific security or compliance requirements, please get in touch. We are happy to provide additional documentation or discuss your organisation's requirements.

Contact Us