Skip to content

Security

Security-conscious by design, conservative by default.

Govvisor is being developed for professional contexts where SR&ED, tax, payroll, financial, client, and proprietary technical information must be handled carefully.

No public uploadsNo login on this websiteNo payment processingServer-validated lead intakeSeparate future application

Principles

Public website data boundaries are intentionally narrow.

This marketing and qualification site collects only limited business contact details through a configured server-side workflow. It is not a channel for confidential project disclosure, application access, or ECI™ assessment.

Data minimization

The public website does not request confidential SR&ED files, payroll records, tax filings, financial statements, or proprietary project documents.

No public uploads

There are no file uploads on this website. Future pilot intake should use a secure, reviewed channel with explicit data handling terms.

Security review ready

Pilot conversations can cover hosting, access control, encryption, retention, incident intake, vendor review, and data residency expectations.

Clear escalation

Security questions and responsible disclosure inquiries should be directed to security@govvisor.com.

Pilot security

Real customer data remains out of scope.

Do not process real customer SR&ED data until a separate controlled application environment, such as app.govvisor.com, is production-ready and approved.

  • Govvisor.com remains a public marketing, qualification, and demonstration-request website only.
  • No unrestricted registration, public application account, customer file upload, or project-data intake is enabled.
  • Canadian data residency, secure storage, encryption, MFA, role-based access, secure sessions, audit logs, backups, and recovery are deployment prerequisites.
  • Privacy, legal, vendor, retention, and security approvals are required before confidential information is introduced.

Review topics

Production controls—not current claims.

These controls are prerequisites for the future authenticated application. Listing them here does not represent that an application environment or its infrastructure is currently operational.

Required

Canadian data residency

Select and verify Canadian hosting and processing locations before real customer SR&ED data is introduced.

Required

Secure data layer

Provision an approved database and object storage with encryption in transit and at rest.

Required

Identity and access

Require invitation-only authentication, MFA, role-based access control, and least-privilege administration.

Required

Secure sessions

Implement secure session management, expiration, revocation, and appropriate protection against account abuse.

Required

Audit and recovery

Enable audit logging, monitored administrative activity, tested backups, and documented recovery procedures.

Required

Legal and vendor approval

Approve privacy disclosures, retention terms, subprocessors, incident handling, and customer agreements before processing.

Have a security question?

Send responsible disclosure, vendor review, or security posture questions to security@govvisor.com. Do not include confidential client or project files in first-contact email.