An enterprise client sends a due-diligence questionnaire.
Attach the evidence pack. The questions about AI governance are already answered inside it.
When a regulator, insurer or enterprise client asks how you govern AI, you hand them evidence, not assurances.
Last updated 5 July 2026
The pack assembles itself from what already happened in your workspace. When someone asks, you export it: no scramble, no write-up after the fact.
Every tool your team uses, each verdict, and the rule behind it.
What happened, what was assessed, who made the call.
Who completed which module, with scores and dates.
Who read and accepted each policy version, when.
Every governance action, in order, ready to show.
Evidence is for the day someone else wants to see it. Three ways that day arrives.
Attach the evidence pack. The questions about AI governance are already answered inside it.
Export the tool register: every tool, its verdict for each kind of data, and the rule behind it.
Open the incident log. The guided assessment walks the notifiable-breach question with a person making the call, never software.
Customer data and server functions are pinned to the Sydney region.
Green, amber or red is computed deterministically from your policy rules.
Only your governance team authenticates. Staff reach HighSign through a shared link.
We do not use your workspace content to train third-party models.
Customer data is hosted in Australia (Supabase, Sydney region), and the application’s server functions are pinned to the same Sydney region, so requests don’t leave the country in normal operation. A small number of sub-processors (see below) may process limited data overseas; where they do, we take reasonable steps to ensure comparable protection consistent with the Australian Privacy Principles.
Every organisation’s workspace is logically isolated: access is scoped to the signed-in user’s own organisation in application code on every request, and the system is designed so that one customer can never read or change another’s data, with row-level security policies at the database as defence in depth. Only your governance team signs in, with roles (owner, admin, approver, reviewer); staff never authenticate at all.
HighSign governs the AI tools and data classes you declare, and the answers your staff request; it does not intercept network traffic, read staff messages, or monitor individuals. Staff tool checks record that a lookup happened, for adoption metrics, but we do not record who made it, and requests and reports carry only the name a person chooses to give so you can reply. This boundary is deliberate: it is what lets the whole team use the tool without being watched.
The single rule the whole product is built around, and the one we hold ourselves to.
Verdicts (green, amber or red) are computed deterministically from your policy rules. No AI model sits in the answer path. Optional AI features, such as drafting a tool’s data-governance profile or mapping a workflow, only run when you switch them on, always produce a draft a human confirms, and can never set a verdict. We do not use your workspace content to train third-party models, and anything an AI feature sends to a provider is limited to the public tool being researched, never your client data.
A governance product that let a model quietly decide verdicts would be governing AI risk with more AI risk. Ours cannot.
HighSign does not yet hold SOC 2 or ISO 27001 certification, and we will not imply otherwise. If you need one for a due-diligence process, send us your questionnaire and we will answer it directly.
| Sub-processor | What it handles | Where |
|---|---|---|
| Supabase | Database, authentication and file storage | Australia (Sydney) |
| Vercel | Application hosting and server compute | Functions pinned to Sydney, with a global edge for static assets |
| Stripe | Subscription billing and payment processing. Card data is handled by Stripe; we never see or store card numbers. | Active only when billing is enabled |
| Resend | Transactional email (sign-in links, notifications) | Active only when email is enabled |
| Anthropic | The optional AI drafting and research features | Active only when you enable them, and sent only public tool information, never your client data |
We do not sell personal information, and we do not run advertising trackers.
You own your workspace data: read it in the app, generate evidence and board packs, and request export or deletion. We create de-identified, aggregated benchmarks across customers (for example which AI tools are commonly approved or restricted, by sector and size band) to improve the Service and report market trends; these never include your client data, staff identities or policy text, and are only ever shared in a form that cannot reasonably be re-identified. The Privacy Policy has the full detail.
We operate under Australia’s Notifiable Data Breaches scheme: if an eligible data breach affecting your information occurred, we would assess it and notify affected customers and the OAIC as required. HighSign itself also includes a guided breach-assessment tool for the incidents you record, and the notifiable call is always a person’s, never automatic. The Service runs on managed, redundant cloud infrastructure with automated backups of the database; formal uptime SLAs are available on the sales-assisted plans.
Security questions, a due-diligence questionnaire, or to request a data processing agreement: hello@howll.ai. HighSign is offered to customers internationally; if you are outside Australia, including in the EU or United Kingdom, and need a specific data-processing arrangement, we will accommodate reasonable requirements where we can. HighSign is a service of CREDITVUE HOLDINGS PTY LTD (ABN 98 666 028 824), 20/663 Newcastle Street, Leederville WA 6007.
HighSign provides operational compliance frameworks and automated governance tooling, not formal legal advice. For certified validation, route your evidence pack to a qualified legal practitioner for sign-off.