AI policy infrastructure for audit confidence

Ik beantwoord de auditor, omdat ik bouwde wat ze controleren.

I’ll answer the auditor — because I built what they’re inspecting.

Govannon AI turns the way your team uses AI into controls you can show. Evidence is continuous, because the policy lives in the platform. Not improvised the week the questionnaire arrives.

Built in the Netherlands. Designed for standards that hold up in diligence.

Evidence pack

  • Model access Named roles
  • Data residency EU paths
  • Prompt and output log Retained
  • Review gate on AI diffs In the pipeline
  • Retention and deletion Written down

Compliance
evidence

  • SOC 2
  • ISO 27001
  • GDPR
  • EU AI Act

Frameworks I build against. Not certifications I claim.

  • EU-based. Amersfoort. The infrastructure mindset stays in Europe.
  • Independent. I built it. I answer for it. No junior bench.
  • Readiness. SOC 2, ISO 27001, GDPR, HIPAA — controls, not a badge wall.

Why Govannon AI

Compliant by construction.

01

Compliance theater vs architecture

Policies on paper don’t satisfy an evidence-driven audit. I build the controls into the stack — so you can prove intent, that the control exists, and that it actually runs.

02

AI policy in the platform

From the rule to the enforcement: access, data residency, logging, review gates, evidence capture. One system. Not a bolted-on checklist someone updates in a slide.

03

Where trust is mandatory

Scale-ups walking into enterprise and regulated sales. Payments, mobility, healthcare-adjacent work, public-sector buyers. The story has to survive procurement, not just the demo.

Platform

What “in the platform” actually means.

Four moves. No transformation program.

  1. 01 — Author Write the policy once. Language an engineer can implement and an auditor can read.
  2. 02 — Enforce Put it where the work is. Repo, pipeline, access, and data paths. If it isn’t enforced, it isn’t a control.
  3. 03 — Record Evidence as a byproduct. Logging and review gates while you ship. Not a separate project the month before.
  4. 04 — Answer Read the system back. The questionnaire comes from the platform, not from memory.

The record

The person who answers the auditor still opens a terminal.

Govannon since 2005. These are roles and systems I have actually held. Not a client logo wall.

Payments, 18 countries CTO of a mobile payments platform across Europe. Ruby, Elixir, clustering.
~250 Kubernetes nodes Cloud project leadership on a mobility platform (Mobiliteitsfabriek). Multi-cluster, GitOps, Argo CD, Kyverno, Terraform. Policy as code.
Audit readiness SOC 2, ISO 27001, GDPR, HIPAA readiness. I design with the EU AI Act in view. Readiness means the control exists and you can show it.
Still codes Most fractional CTOs stopped. I didn’t. Open-source Elixir other teams run: cloudex, set_locale, ecto_translate. github.com/smeevil
27+ years Shipping software since the late nineties. Heineken server parks. ABN AMRO’s early crowdfunding stack. Then platforms that have to stay up.

When I review the architecture, I’m not guessing. I can open a terminal and prove it.

Before they arrive

Stress-test the AI stack before the auditor does.

I don’t sell a certificate. I build the architecture the certificate depends on. If you want a logo for the procurement slide and nothing in the repo, I’m not your guy.

  1. You bring the stack and the questionnaire you’re afraid of.
  2. I tell you what would fail, and what is already sound.
  3. We put the failing controls into the platform.
  4. The next audit is a readout. Not a fire drill.

Contact

Govannon AI

Gerard de Brieder. Govannon since 2005. Amersfoort, Netherlands.

+31 6 2496 3568

info@govannon.nl

linkedin.com/in/smeevil

Parent company: govannon.nl