Security and Trust

Where governed AI application data goes, in plain English

No black box. This page states exactly which providers process GovSight and PursuitWorks application data, how AI data use works, and what we do and do not claim about certifications.

What application data goes where

When you use GovSight-powered applications, your account details, organization records, uploaded documents, generated artifacts, and execution context are stored in Supabase. The application is served from Vercel, so requests pass through Vercel infrastructure. When an AI-assisted capability runs, the prompts and scoped content for that run are transmitted to Anthropic for processing and the output is returned to your workspace.

Customers are responsible for determining what information they are authorized to process through PursuitWorks and any connected commercial third-party AI services, including classified information, CUI, export-controlled materials, or other restricted content. GovSight does not inspect every uploaded document to block AI usage based on restricted markings, so your organization decides what may be processed through commercial third-party AI services.

Subprocessors

Each provider below maintains its own security and compliance program. PursuitWorks currently uses Vercel for application hosting and Supabase for backend services. Vercel and Supabase publish their own provider-level security and compliance programs, including SOC 2 Type 2 coverage. Provider controls help support PursuitWorks infrastructure, but they do not make GovSight or PursuitWorks FedRAMP, CMMC, SOC 2, or government certified.

GovSight subprocessors
ProviderRoleWhat it handles
VercelApplication hostingServes the application and processes requests in transit, including request metadata such as IP address.
SupabaseDatabase, authentication, and storageStores account records, organization data, uploaded documents, and generated artifacts. Handles login and session management.
AnthropicAI processing via APIProcesses prompts, the content you scope into a capability run, and generated outputs when you run an AI-assisted capability.
StripePaymentsProcesses subscription payments. GovSight does not store credit card numbers; we receive transaction confirmations and subscription status.

Your content is not used to train models

PursuitWorks uses Anthropic API access to process prompts, uploaded content, and generated outputs. Under Anthropic API policy, Anthropic does not use API inputs or outputs to train its models unless the API customer separately opts in or otherwise provides data for model improvement. GovSight processes uploaded content and generated outputs to provide and operate PursuitWorks. GovSight does not use customer proposal content to train AI models.

AI data use follows Anthropic API policy

01

Encryption

Traffic between browsers and GovSight applications is encrypted in transit over HTTPS/TLS. Connections to backend providers are encrypted, and Supabase encrypts stored data at rest.

02

Data retention and deletion

Account information and content are retained while an account is active. Upon account termination, content is deleted within 90 days except where retention is required by law or dispute resolution.

03

Role-based access control

Workspace members hold defined roles. Server-side permission checks cover mission creation, capability runs, member management, billing, and deletion.

04

Human review gates and audit trail

AI-generated outputs are drafts. Human approval is required before drafts become approved mission content, and audit trails record runs, artifacts, decisions, and sources.

05

Certification status

PursuitWorks does not claim FedRAMP, CMMC, SOC 2, or government certification. Sensitive handling requirements should be reviewed with legal and security stakeholders before use.

06

Workspace isolation

Each organization lives in its own organization scope. Row-level security restricts documents, artifacts, and retrieval to the user organization.

Role summary

01OwnerFull control, including billing, member management, and workspace deletion.
02AdminManages missions, members, and capability runs without billing or deletion authority.
03MemberCreates missions, runs capabilities, and edits proposal content.
04ViewerRead-only access to mission content. Cannot run capabilities or edit.

Security contact and vulnerability disclosure

If you believe you have found a security vulnerability in GovSight or any GovSight application, email support@govsight.co with enough detail to reproduce the issue. The same address handles security questionnaires, data-handling questions, and deletion or export requests. A person reads it.

Security and Trust | GovSight