Legal

Sub-processor Disclosure

Last updated: June 2026

Govalta uses the following third-party sub-processors to deliver its platform and assessment services. Each sub-processor is authorized to process customer data only to the extent necessary to perform the stated service. Govalta maintains data processing agreements with each sub-processor where required.

If you have questions about our sub-processors or wish to object to the use of a particular sub-processor, contact us at contact@govalta.com.

Vercel, Inc.

Hosting & Infrastructure · United States

Privacy Policy ↗
PurposeCloud infrastructure and edge delivery

Govalta's web application is hosted and served via Vercel's cloud infrastructure. Vercel processes request metadata (IP addresses, request timing, and similar technical data) as part of delivering the application to users. No personal data or uploaded content is stored by Vercel beyond standard request logs.

Supabase, Inc.

Storage & Database · United States

Privacy Policy ↗
PurposeDatabase, file storage, and real-time infrastructure

Govalta uses Supabase for its primary database, file storage (evidence uploads), and authentication infrastructure. All uploaded evidence documents and application data are stored in Supabase infrastructure. Data is encrypted at rest and in transit.

WorkOS, Inc.

Identity & Access · United States

Privacy Policy ↗
PurposeEnterprise authentication and single sign-on

Govalta uses WorkOS to provide enterprise SSO (SAML 2.0 / OIDC) and authentication flows for enterprise customers. WorkOS processes authentication credentials and user identity assertions during login. No remediation evidence or validation records are transmitted to WorkOS.

Anthropic, PBC

AI Inference · United States

Privacy Policy ↗
PurposeAI inference for the Govalta Assessment Engine

Govalta's assessment engine uses Anthropic's API to process extracted text from uploaded evidence documents. Anthropic receives structured text inputs and returns structured assessment outputs. Anthropic does not use customer inputs or outputs to train its models under Govalta's enterprise API agreement. Anthropic is bound by its API usage policies. No raw evidence files are transmitted to Anthropic — only text extracted by Govalta's parsing pipeline.

Changes to This Disclosure

Govalta will update this disclosure when sub-processors are added or removed. For design partners and customers with DPA agreements that require advance notice of sub-processor changes, notice will be provided in accordance with the terms of your agreement.