Security & Compliance
Your data stays in your tenant, and we have no route to it
The GovConvert security model is architectural. The software runs inside your own tenant. We hold no copy of your data, no credentials, and no network path into your environment.
Where your data lives
The full model in one diagram. Everything sensitive sits inside the boundary you already control and assess.
Your boundary · your Azure subscription
Your Azure tenant
- GovConvert App Service + PostgreSQL + Key Vault
- Your AI models (e.g. Azure OpenAI) — prompts stay in-tenant, in-memory only
- Audit log → your Microsoft Sentinel
Your M365 GCC High
- CUI lives here, in the SharePoint library you already secured. GovConvert links to it and does not copy it out.
- Entra ID SSO — your MFA and Conditional Access apply
the only thing that ever crosses: license key · version number · random install ID
GovConvert (the vendor)
We hold no credentials, no network path, and no read access. Our publisher service cannot reach your CUI, your documents, or your records. The architecture provides no route to them.
The controls, concretely
Deploys into your tenant
The full stack — App Service, PostgreSQL, Key Vault, Storage — provisions inside your own Azure subscription and resource group. Commercial, Azure Government, or alongside your M365 GCC High environment.
CUI is never stored in GovConvert
Sensitive documents stay in the M365 GCC High SharePoint library you already secured and assessed. GovConvert links to them; it does not copy them into its own database.
Tamper-evident audit trail
A SHA-256 hash-chain audit log runs by default. Each record is chained to the one before it, so an edit made outside the application is detectable. The log forwards to Microsoft Sentinel.
Granular RBAC: 105 permissions
105 permissions across 9 categories, mapped role by role, so each person sees only what their role requires. Partner and guest roles keep external users tightly scoped.
Your SSO, your Conditional Access
Sign-in uses Microsoft 365 SSO. Your existing MFA, Conditional Access, and device policies apply automatically. GovConvert adds no separate sign-in path around them.
Encryption, inherited from your cloud
Data is encrypted in transit and at rest by the Azure and M365 controls you already run, inside the boundary your assessor already reviewed.
Updates you pull, never pushed
Each new version is published with a changelog. Your admin applies it in a maintenance window. Every update carries a verified signature and takes an automatic database backup first.
Deployment documentation built in
The deployment ships with copy-ready documentation for the system itself — the paragraphs your SSP needs about how GovConvert is architected, its data flows, and its shared-responsibility split, ready to adapt.
How we fit into compliance — and what stays yours
No software makes an organization compliant, and you should be suspicious of any vendor who says otherwise. Compliance belongs to you. What we control is whether the product widens your scope or stays out of the way. The split is below.
How the architecture helps
GovConvert runs inside the boundary you already assess, so it adds no external service to your assessment scope.
- Access Control (AC): RBAC with 105 permissions, M365 SSO, partner/guest scoping
- Audit & Accountability (AU): Hash-chain audit log on by default, shipped to Sentinel
- Identification & Authentication (IA): Your Entra ID, MFA, and Conditional Access — no separate credential store
- System & Communications Protection (SC): In-tenant deployment; CUI does not transit or rest outside your boundary
What stays yours
These parts remain your organization’s responsibility. No vendor can provide them.
- Physical protection, personnel security, and awareness training
- Your organizational policies and procedures
- The rest of your environment — endpoints, network, M365 configuration
- The assessment itself: your assessor, your evidence, your scope
Designed against the standards you already work to
DFARS 252.204-7012 and NIST SP 800-171 govern your CUI, and NIST SP 800-53 governs the federal systems you connect to. GovConvert is built around those: no documents stored, deployment inside the boundary you already operate, RBAC and audit on by default, and no vendor access to any of it.
What does leave your tenant
From your deployment to us
Three items only: your license key, your version number, and a random install ID. That is enough to validate your subscription and offer updates. It includes no CUI, no documents, and no records.
Subprocessors
Stripe processes billing. It receives your billing contact and payment method, and nothing from your tenant. Microsoft is your own cloud provider, under your own agreements rather than ours. This marketing site uses Calendly for demo booking and Google Analytics with consent. Neither has any connection to the product.
Building your SSP?
We send you a security overview of the GovConvert deployment, written for inclusion in your System Security Plan — architecture, data flows, and the shared-responsibility split, in assessor-friendly language.
Request the security overviewBring your security team to the demo
Thirty minutes with the architecture open for questions. We answer them on the call.