What we do, and what we do not claim.
We score other companies' compliance posture, so ours had better be legible. Every control below carries its real state. Where something is not built yet, it says planned — because a security page that reads like a brochure is worth nothing to the person reading it.
02 — DATA CLASSIFICATION
GovExpress runs on public federal data. The most sensitive thing we hold is a company describing itself.
What we hold
Public federal records — SAM.gov registrations, USASpending and FPDS obligations, the FedRAMP Marketplace, GSA CALC+, SBIR.gov — plus the business information you submit in a report intake, your account email, and billing records held by our payment processor.
What we will not hold
No controlled unclassified information. No classified information. No export-controlled technical data. No consumer personal information, no health information, and no payment card numbers. Our terms prohibit submitting any of it, and the service is not built to receive it.
Why the ceiling is low on purpose
Classified awards are exempt from public reporting under FAR 4.606(c) and the government's supplier risk system is government-only. We have no route to either, so there is nothing of that sensitivity in the product to lose.
If you send us something you should not
Tell us at security@govexpress.ai and we will delete it and confirm the deletion. Do not send a second copy to prove the first one existed.
03 — ENCRYPTION IN TRANSIT
ENCRYPTION AT REST
04 — HOSTING AND REGION
govexpress.ai — this marketing site — is a static build with no server-side code and no database. It is stored in Amazon S3 and served through Amazon CloudFront, in AWS region us-east-1. CloudFront is a global network, so the page you are reading may have been served from an edge location near you; the origin and every stored byte stay in the United States. No customer data touches this site.
app.govexpress.ai — the signed-in application, where intake and reports live — is a separate deployment. Provider: Amazon Web Services. The application runs on ECS Fargate — an API service, a worker service and a vector-store service — with Amazon RDS for PostgreSQL 15, Amazon ElastiCache for Redis, Amazon S3 for object storage, an Application Load Balancer, and Amazon CloudFront in front of both this site and the application.. Region: US East (N. Virginia), us-east-1, for all compute, database, cache and storage. CloudFront also serves from edge locations outside the United States: this site and govexpressai.com use the all-locations price class, and app.govexpress.ai uses the North America and Europe price class.. We publish these rather than saying "the cloud", because a buyer assessing us needs to know where their data sits.
05 — AUTHENTICATION AND ACCESS CONTROL
GovExpress is a small team, which cuts both ways: the number of people who could touch customer data is very small, and we do not have a security department. We would rather tell you that than imply a staffed function that does not exist.
06 — YOUR DATA IS NOT TRAINING DATA
GovExpress does not use Customer Data to train, fine-tune, evaluate, or benchmark any machine-learning model, its own or a third party's. This applies in aggregate and in de-identified form. GovExpress does not sell Customer Data and does not share it for cross-context behavioral advertising. There is no opt-out to configure and no plan tier under which this changes.
This is restated here because it is a security property, not only a privacy one: it bounds where your data can travel. The same paragraph is a binding term of the privacy policy and of the terms of service. It binds GovExpress. It is not a claim about what our service providers have signed — we have not executed a data processing agreement with any of them, and the service provider page says so and sets out the standard such an agreement will have to meet.
07 — HOW THE SCORE IS CONTAINED
Scoring runs server-side. Clients receive final scores, bands, and narratives only — never indicator IDs, weights, thresholds, or evaluation logic. That is an architectural commitment, not a configuration setting, and a build gate fails the release if any of it reaches a public page.
The reason it is worth saying out loud is that the alternative is the industry norm. A score computed in the browser, or delivered with its component parts attached, is a score anyone can take apart and rebuild — and the companies being scored are the ones with the strongest reason to try. Keeping the evaluation server-side is what makes a published methodology safe to publish: you can read what the model looks at and why, without being handed the means to game it.
Attempting to reconstruct the methodology — by inspection, by systematic querying, or by training a model on our outputs — is a breach of the acceptable use policy.
08 — SERVICE PROVIDERS
These service providers process data on our behalf. The service provider page carries the full table, what each one receives, and the date it was last reviewed; the privacy policy carries it too, along with the third parties this marketing site talks to. No data processing agreement has been executed with any of them yet, and that page says so.
We give notice before adding a service provider that will handle customer data, so you can object before it starts.
09 — INCIDENT RESPONSE
If we confirm a security incident affecting customer data, we notify affected customers by email within 72 hours of confirming it, and we notify regulators where the law requires it. The notice states what happened, what data was involved, what we have done, and what you should do. We send it even when the answer to the last question is "nothing".
We do not wait for a complete investigation to tell you an incident happened. A first notice inside the window with partial facts, followed by updates, beats a polished one that arrives late.
A formal, tested incident response runbook is planned, not written. Today the process is the commitment above and a very short chain of command.
10 — WHAT WE DO NOT CLAIM
Most security pages are a list of logos. This is the list of logos we do not have. Every line below is a claim we are not making.
We are not FedRAMP Certified
GovExpress holds no FedRAMP certification at any class or impact level, holds no legacy authorization either, and is not listed in the FedRAMP Marketplace. We report other companies’ FedRAMP status from that Marketplace; we have none of our own to report. (The 2026 Consolidated Rules retired “Authorized” as the status term in favour of “Certified” — the change in wording does not change what we hold, which is nothing.)
We are not a C3PAO or a 3PAO
We are not a Certified Third-Party Assessment Organization, not a FedRAMP Third Party Assessment Organization, and not accredited by the Cyber AB or any other body. We cannot assess you, and an assessor cannot use our output as evidence.
We are not a certification body
A Federal Readiness Score certifies nothing. It is a diagnostic computed from public data, and presenting it as a certification or a government endorsement is a breach of our terms.
We hold no SOC 2, ISO 27001, or CMMC certification
No audit has been performed and no report exists. If that changes we will name the auditor, the report type, and the period, and you will be able to ask for the report itself.
We are not authorized for CUI or classified information
The service has no authorization to receive, store, or process controlled unclassified information or classified information, and no environment built for it.
11 — FOUND A VULNERABILITY?
Report it to security@govexpress.ai. We work to a 90-day coordinated disclosure window and we will not pursue you for good-faith research. The scope, the rules, the safe harbour, and the honest note that there is no bug bounty are all on the vulnerability disclosure page.
The machine-readable version is at /.well-known/security.txt.