Security

Principles, stated without borrowed credibility.

This page describes how the platform is built. It names no certification, because TwinGov holds none at the time of writing, and a badge here would be found out in the first serious evaluation.

What we hold, and what we do not

TwinGov has no SOC 2 report, no ISO certification, no FedRAMP authorisation and no government security approval. Nothing on this site displays a compliance badge. If a formal attestation is a requirement of your procurement, raise it in the first exchange and you will get a direct answer about what exists, what is planned and what is not.

Separation

Each institution works in its own workspace, configured on its own data. Workspaces are separated from one another, are private by default and are excluded from public indexing. A public demonstration model, where one exists, is a separate thing built from open data.

Access

  • Users hold roles that determine what they can see and do inside their institution's workspace.
  • Analyses and scenarios record who produced them and on what inputs.
  • Access is granted by the institution, not by us on its behalf.

Hosting

The hosting region for a deployment is set to what the customer’s rules require, and confirmed in writing before signature. We will say no to a constraint we cannot meet rather than agree and discover it later.

Reporting a vulnerability

If you believe you have found a security issue in this website or in the platform, write to hello@twingov.app with enough detail to reproduce it. We will confirm receipt, and we will not pursue anyone who reports in good faith and does not exfiltrate or damage data in the process.

A dedicated security contact address and a published disclosure policy are on the list of things to add. Until they exist, the address above is the route.