Evidence

When a regulator, insurer or enterprise client asks how you govern AI, you hand them evidence, not assurances.

Last updated 5 July 2026

The evidence pack

What you hand them, page by page.

The pack assembles itself from what already happened in your workspace. When someone asks, you export it: no scramble, no write-up after the fact.

  1. Tool register

    Every tool your team uses, each verdict, and the rule behind it.

  2. Incident log with breach assessments

    What happened, what was assessed, who made the call.

  3. Training records

    Who completed which module, with scores and dates.

  4. Attestation history

    Who read and accepted each policy version, when.

  5. The chronological audit trail

    Every governance action, in order, ready to show.

Who asks

Who asks, what you hand them.

Evidence is for the day someone else wants to see it. Three ways that day arrives.

An enterprise client sends a due-diligence questionnaire.

Attach the evidence pack. The questions about AI governance are already answered inside it.

Your insurer asks what controls you have around AI.

Export the tool register: every tool, its verdict for each kind of data, and the rule behind it.

Something goes wrong.

Open the incident log. The guided assessment walks the notifiable-breach question with a person making the call, never software.

Hosting

Hosted in Australia

Customer data and server functions are pinned to the Sydney region.

Verdicts

No AI in the answer path

Green, amber or red is computed deterministically from your policy rules.

Access

Staff never log in

Only your governance team authenticates. Staff reach HighSign through a shared link.

Data use

No training on your data

We do not use your workspace content to train third-party models.

Data residency

Australian hosting and data residency

Customer data is hosted in Australia (Supabase, Sydney region), and the application’s server functions are pinned to the same Sydney region, so requests don’t leave the country in normal operation. A small number of sub-processors (see below) may process limited data overseas; where they do, we take reasonable steps to ensure comparable protection consistent with the Australian Privacy Principles.

Access

One door in, and it is not for staff

Every organisation’s workspace is logically isolated: access is scoped to the signed-in user’s own organisation in application code on every request, and the system is designed so that one customer can never read or change another’s data, with row-level security policies at the database as defence in depth. Only your governance team signs in, with roles (owner, admin, approver, reviewer); staff never authenticate at all.

HighSign governs the AI tools and data classes you declare, and the answers your staff request; it does not intercept network traffic, read staff messages, or monitor individuals. Staff tool checks record that a lookup happened, for adoption metrics, but we do not record who made it, and requests and reports carry only the name a person chooses to give so you can reply. This boundary is deliberate: it is what lets the whole team use the tool without being watched.

AI safety

No AI in the answer path

The single rule the whole product is built around, and the one we hold ourselves to.

Verdicts (green, amber or red) are computed deterministically from your policy rules. No AI model sits in the answer path. Optional AI features, such as drafting a tool’s data-governance profile or mapping a workflow, only run when you switch them on, always produce a draft a human confirms, and can never set a verdict. We do not use your workspace content to train third-party models, and anything an AI feature sends to a provider is limited to the public tool being researched, never your client data.

A governance product that let a model quietly decide verdicts would be governing AI risk with more AI risk. Ours cannot.

Security practices

Encryption, secrets and audit

  • In transit: all traffic is served over TLS with HSTS, and the app sets a strict security-header and content-security policy.
  • At rest: data is encrypted at rest by our hosting provider.
  • Secrets: API keys and service credentials live only in server-side configuration, never in the browser or the code repository.
  • Audit: governance actions (policy changes, decisions, exceptions, attestations and incidents) are recorded to a chronological activity log you can show an auditor.

HighSign does not yet hold SOC 2 or ISO 27001 certification, and we will not imply otherwise. If you need one for a due-diligence process, send us your questionnaire and we will answer it directly.

Sub-processors

The third parties that help us run the Service

Sub-processorWhat it handlesWhere
SupabaseDatabase, authentication and file storageAustralia (Sydney)
VercelApplication hosting and server computeFunctions pinned to Sydney, with a global edge for static assets
StripeSubscription billing and payment processing. Card data is handled by Stripe; we never see or store card numbers.Active only when billing is enabled
ResendTransactional email (sign-in links, notifications)Active only when email is enabled
AnthropicThe optional AI drafting and research featuresActive only when you enable them, and sent only public tool information, never your client data

We do not sell personal information, and we do not run advertising trackers.

Ownership

Your data is yours

You own your workspace data: read it in the app, generate evidence and board packs, and request export or deletion. We create de-identified, aggregated benchmarks across customers (for example which AI tools are commonly approved or restricted, by sector and size band) to improve the Service and report market trends; these never include your client data, staff identities or policy text, and are only ever shared in a form that cannot reasonably be re-identified. The Privacy Policy has the full detail.

Breach response

Availability, continuity and breach response

We operate under Australia’s Notifiable Data Breaches scheme: if an eligible data breach affecting your information occurred, we would assess it and notify affected customers and the OAIC as required. HighSign itself also includes a guided breach-assessment tool for the incidents you record, and the notifiable call is always a person’s, never automatic. The Service runs on managed, redundant cloud infrastructure with automated backups of the database; formal uptime SLAs are available on the sales-assisted plans.

Due diligence

Questions, or a questionnaire to complete

Security questions, a due-diligence questionnaire, or to request a data processing agreement: hello@howll.ai. HighSign is offered to customers internationally; if you are outside Australia, including in the EU or United Kingdom, and need a specific data-processing arrangement, we will accommodate reasonable requirements where we can. HighSign is a service of CREDITVUE HOLDINGS PTY LTD (ABN 98 666 028 824), 20/663 Newcastle Street, Leederville WA 6007.

HighSign provides operational compliance frameworks and automated governance tooling, not formal legal advice. For certified validation, route your evidence pack to a qualified legal practitioner for sign-off.