Security
PolicyHQ handles policy intelligence for organizations whose work depends on it being right + private. This page documents the controls that back that promise.
Last updated: September 30, 2026
Encryption
At rest: all customer data is stored in a managed Postgres database, encrypted with AES-256 at the database volume layer. Backup snapshots inherit the same encryption.
In transit: all client connections to the app and all server-to-database connections use TLS 1.3. HTTP requests are upgraded to HTTPS via a Strict-Transport- Security header (1-year max-age, includeSubDomains, preload).
Internal services: all outbound calls to subprocessors (AI model, translation, email and database providers) use TLS. API keys are stored as encrypted environment secrets in the hosting platform — never committed to source.
Data residency
Primary database: hosted in Japan (Tokyo). Backups stay in the same region. No customer body data leaves Japan without an explicit per-request flow.
Application layer: primary compute region Japan (Tokyo). Static assets are distributed via a global edge network.
AI processing: text sent for generation, embeddings and speech-to-text is processed by AI model API providers in the United States; machine translation is processed in the European Union (Germany). Providers are contractually barred from training on customer data. Countries, purposes and safeguards for every category are on the subprocessor page.
Access control
PolicyHQ uses a multi-tenant model with three role tiers: owner, admin, member. Cross-organization data access is blocked at the database- query layer — every read path filters by organization_id membership.
Projects can be marked private with explicit membership lists, supporting use cases like outside-counsel collaboration or M&A research where org-wide visibility isn’t appropriate.
Authentication via OAuth single sign-on or email and password; SAML SSO support is on the near-term roadmap. Multi-factor authentication is available and will be enforceable at the organization level.
Audit logging
Every membership change, role promotion, project visibility change, invitation, removal, and workspace edit is recorded with actor + timestamp. Mutations to tracked entities (bills, comments, stakeholders) are versioned via a bitemporal history table — you can query “what was this bill’s status on date X?” and “when did we record that change?”.
Organization owners can review their org’s audit stream from the settings page.
Data retention + deletion
Customer-controlled: organization owners can delete their organization and all associated data at any time from settings. Deletion cascades through every related table (members, projects, workspaces, comments, notifications) within the same transaction.
Backups: point-in-time recovery backups are retained for 7 days, after which they age out automatically. Deleted customer data exits backups on the standard backup-aging schedule.
Logs: hosting request logs are retained for 30 days; error-monitoring logs are retained for 90 days with PII scrubbed.
Incident response
Production errors flow through an error-monitoring service with PII scrubbed before transmission. On-call rotation: founder-led at this stage. Customer-impacting incidents are communicated within 24 hours via in-app notification and email to organization owners.
Subprocessor security incidents are tracked via vendor status pages and notices; we re-broadcast to affected customers when a vendor outage materially affects PolicyHQ functionality.
Compliance posture
PolicyHQ is preparing for SOC 2 Type 1 certification. We can provide a detailed CAIQ-Lite or SIG-Lite questionnaire response on request to enterprise customers. A signed Data Processing Agreement is available for customers subject to GDPR or APPI.
Our core infrastructure providers (database, hosting and identity) hold SOC 2 Type 2 and/or ISO 27001 certifications. The subprocessor page lists every category with its country and safeguards; the named, vendor-by-vendor list is available to customers when signed in, and in the DPA annex on request.
Reporting a security issue
Email security@geminigr.com with the details. We aim to acknowledge within 24 hours and follow up with a remediation timeline within 72 hours.
Please don’t publicly disclose a vulnerability before we’ve had a chance to fix it — we’ll happily credit the researcher in the changelog once the fix is live.