Security

Sensitive checks deserve
careful handling.

GovFin is built so that verification evidence is protected in transit and at rest, access is limited to the people who need it, and important actions can be traced. This page describes our approach without exposing internal architecture detail.

In transit & at rest

Protected from submission to outcome.

  • Encrypted transport is assumed for all traffic.
  • Supporting documents are stored outside the public web root.
  • Filenames are opaque and integrity is verified with hashing.
  • Downloads require authorisation every time.

Access & accountability

Least privilege, with a record.

  • Client users are limited to their own organisation's requests.
  • Staff and read-only auditor roles are separated.
  • Material workflow and document actions are recorded.
  • Suspended accounts and sessions are invalidated.

Being hardened

What we are actively strengthening.

We would rather name what is still in progress than imply it is finished.

Malware scanning

An integrated scan-then-promote pipeline before any real document is processed.

Staff MFA / SSO

Privileged identity controls and separation of duties for release.

Tamper-evident audit

Cryptographic chaining and broader event coverage.

Report verification

A secure public model to authenticate a GovFin report without exposing its contents.

GovFin is an unapproved preview and does not process real identity documents, live payments or regulated checks until the secured storage and scanning pipeline are operational and launch approval is recorded. Please do not submit real personal documents through the public site.

Security or privacy question?

Talk to the GovFin team.

Contact GovFin