Data minimization
The public website does not request confidential SR&ED files, payroll records, tax filings, financial statements, or proprietary project documents.
Security
Govvisor is being developed for professional contexts where SR&ED, tax, payroll, financial, client, and proprietary technical information must be handled carefully.
Principles
This marketing and qualification site collects only limited business contact details through a configured server-side workflow. It is not a channel for confidential project disclosure, application access, or ECI™ assessment.
The public website does not request confidential SR&ED files, payroll records, tax filings, financial statements, or proprietary project documents.
There are no file uploads on this website. Future pilot intake should use a secure, reviewed channel with explicit data handling terms.
Pilot conversations can cover hosting, access control, encryption, retention, incident intake, vendor review, and data residency expectations.
Security questions and responsible disclosure inquiries should be directed to security@govvisor.com.
Pilot security
Do not process real customer SR&ED data until a separate controlled application environment, such as app.govvisor.com, is production-ready and approved.
Review topics
These controls are prerequisites for the future authenticated application. Listing them here does not represent that an application environment or its infrastructure is currently operational.
Select and verify Canadian hosting and processing locations before real customer SR&ED data is introduced.
Provision an approved database and object storage with encryption in transit and at rest.
Require invitation-only authentication, MFA, role-based access control, and least-privilege administration.
Implement secure session management, expiration, revocation, and appropriate protection against account abuse.
Enable audit logging, monitored administrative activity, tested backups, and documented recovery procedures.
Approve privacy disclosures, retention terms, subprocessors, incident handling, and customer agreements before processing.
Send responsible disclosure, vendor review, or security posture questions to security@govvisor.com. Do not include confidential client or project files in first-contact email.