{"id":3553,"date":"2026-04-23T17:29:00","date_gmt":"2026-04-23T17:29:00","guid":{"rendered":"https:\/\/www.gosearch.ai\/blog\/?p=3553"},"modified":"2026-04-30T20:24:39","modified_gmt":"2026-04-30T20:24:39","slug":"gosearch-security-data-governance","status":"publish","type":"post","link":"https:\/\/www.gosearch.ai\/blog\/gosearch-security-data-governance\/","title":{"rendered":"GoSearch AI Enterprise Search: SOC 2, HIPAA, GDPR, CCPA Compliant"},"content":{"rendered":"\n<p>Enterprise AI search introduces a new category of security and compliance questions. Which data can the AI see? Who controls where it&#8217;s stored? What happens to queries after they&#8217;re processed? Can it be deployed in regulated industries like healthcare? Determining which AI enterprise search platform is compliant with your organization&#8217;s requirements is essential. <\/p>\n\n\n\n<p>This guide answers all of those questions based on <a href=\"https:\/\/www.gosearch.ai\/product\/security\" target=\"_blank\" rel=\"noreferrer noopener\">GoSearch&#8217;s current, verified compliance posture.\u00a0<\/a><\/p>\n\n\n\n<p><strong>Quick Answer:<\/strong> GoSearch is an AI enterprise search platform that is SOC 2 Type II certified, HIPAA compliant, GDPR compliant, and CCPA compliant. It supports bring-your-own-cloud (BYOC) deployment across AWS, Azure, Google Cloud, and other environments, single-tenant architecture, zero data retention agreements with LLM providers, and granular permission-aware access controls. It is an active, fully supported agentic enterprise search platform suitable for regulated industries including healthcare.<\/p>\n\n\n\n<div style=\"height:50px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<h2 class=\"wp-block-heading\">GoSearch&#8217;s Compliance Certifications<\/h2>\n\n\n\n<div style=\"height:10px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<h3 class=\"wp-block-heading\">SOC 2 Type II<\/h3>\n\n\n\n<p>GoSearch is SOC 2 Type II certified, verified by a third-party auditor, confirming its commitment to the safety of data collection, transportation, and storage. SOC 2 Type II is the most rigorous version of the SOC 2 framework. It requires an independent auditor to assess not just whether controls exist, but whether they operated effectively over an extended period of time. For enterprise buyers evaluating AI search platforms, SOC 2 Type II certification is the baseline signal that a vendor&#8217;s security posture has been independently validated.<\/p>\n\n\n\n<div style=\"height:10px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<h3 class=\"wp-block-heading\">HIPAA Compliance<\/h3>\n\n\n\n<p>GoSearch is HIPAA compliant. GoSearch&#8217;s HIPAA compliant systems ensure personal data is handled with strict access controls, encryption, and auditability \u2014 the three pillars of HIPAA&#8217;s technical safeguard requirements under the Security Rule.<\/p>\n\n\n\n<p>GoSearch is a suitable platform for organizations operating in regulated healthcare environments and handling protected health information (PHI). Healthcare organizations, health-tech companies, and enterprise teams with PHI workloads can evaluate GoSearch as a compliant enterprise search and AI platform.&nbsp;<\/p>\n\n\n\n<p>For healthcare organizations with specific compliance requirements, GoSearch&#8217;s combination of HIPAA compliance, single-tenant architecture, BYOC deployment, and zero data retention with LLM providers creates a governance framework designed for regulated data environments.<\/p>\n\n\n\n<div style=\"height:10px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<h3 class=\"wp-block-heading\">GDPR Compliance<\/h3>\n\n\n\n<p>GoSearch is GDPR compliant, complying with EU regulation, protecting individual data privacy, and enabling user control. For enterprises operating across the European Union or processing the personal data of EU residents, GDPR compliance governs how data is collected, stored, accessed, and deleted. GoSearch&#8217;s GDPR posture includes support for data access and erasure requests and minimization of data collection, both core requirements of the regulation.<\/p>\n\n\n\n<div style=\"height:10px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<h3 class=\"wp-block-heading\">CCPA Compliance<\/h3>\n\n\n\n<p>GoSearch is regularly assessed for CCPA compliance, minimizes data collection, and supports user-controlled data access and erasure. For organizations operating in California or subject to California privacy law, CCPA compliance is increasingly a procurement requirement alongside GDPR and SOC 2.<\/p>\n\n\n\n<div style=\"height:50px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<h2 class=\"wp-block-heading\">GoSearch Supports Bring Your Own Cloud (BYOC)<\/h2>\n\n\n\n<p>GoSearch&#8217;s bring-your-own-cloud capability is an active, fully supported deployment option. With BYOC, all enterprise search security measures are entirely under your control. Your data stays within your AWS, Azure, Google Cloud, or other environment. This means GoSearch can be deployed inside your organization&#8217;s existing cloud infrastructure, ensuring that enterprise data never leaves your controlled environment.\u00a0<\/p>\n\n\n\n<p>For organizations with strict data residency requirements, data sovereignty mandates, or regulatory obligations that prohibit data leaving specific geographic boundaries or cloud accounts, BYOC is the deployment model that satisfies those requirements.<\/p>\n\n\n\n<p>BYOC is particularly relevant for:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>Regulated industries<\/strong> including healthcare, financial services, and government, where data residency is a compliance requirement<\/li>\n\n\n\n<li><strong>Organizations with existing cloud agreements<\/strong> that require all processing to occur within their contracted environments<\/li>\n\n\n\n<li><strong>Enterprise security teams<\/strong> that require full visibility and control over where data is stored and processed<\/li>\n\n\n\n<li><strong>Data-sovereignty buyers<\/strong> in jurisdictions with strict requirements about where organizational data can reside<\/li>\n<\/ul>\n\n\n\n<p>The BYOC option complements GoSearch&#8217;s single-tenant architecture, in which each GoSearch instance is hosted in its own VPC and only serves your company. Whether deployed in GoSearch&#8217;s managed infrastructure or your own cloud environment, your instance is isolated from other tenants.<\/p>\n\n\n\n<div style=\"height:50px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<h2 class=\"wp-block-heading\">How GoSearch Handles AI Data Governance<\/h2>\n\n\n\n<p>AI-powered enterprise search introduces governance questions that go beyond traditional software. The core concern: when employees query an AI that&#8217;s connected to company data, what happens to that data?<\/p>\n\n\n\n<p>GoSearch addresses this through several interlocking controls.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Zero Data Retention with LLM Providers<\/h3>\n\n\n\n<p>GoSearch has zero data retention agreements with LLM providers, ensuring data is used only for immediate purposes. User data will not be stored or used to train AI models.<\/p>\n\n\n\n<p>This is a significant governance assurance. When a GoSearch user asks a question that requires an LLM to generate a response, the data passed to the LLM is not retained by the model provider, is not used to train future models, and is not accessible after the response is generated. For organizations concerned about proprietary information or regulated data appearing in third-party AI training datasets, zero data retention agreements directly address that risk.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Permission-Aware Search and Access Governance<\/h3>\n\n\n\n<p>GoSearch follows source-level permissions and applies the principle of least privilege (PoLP) to show only authorized resources. This means that when an employee searches GoSearch, they see only the content they are already authorized to access in the underlying source systems. An employee cannot use GoSearch to surface content they wouldn&#8217;t be able to access directly in Salesforce, Confluence, Google Drive, or any other connected tool.<\/p>\n\n\n\n<p>This is a critical distinction for enterprise security teams: GoSearch does not create new access pathways to data. It respects and enforces the permissions that already exist in your connected systems.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Federated Search and Data Indexing Controls<\/h3>\n\n\n\n<p>GoSearch offers two approaches to data access: indexed search and real-time federated search. Federated search options provide real-time fetching of data, keeping sensitive information off GoSearch&#8217;s system and protected from exposure.<\/p>\n\n\n\n<p>For organizations with particularly sensitive data that should never be indexed, federated search allows GoSearch to retrieve and process information in real time without storing it. Granular data indexing controls enable enterprises to customize which data is shared and indexed on GoSearch \u2014 so organizations can choose exactly what enters the index and what remains exclusively in the source system.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">LLM Flexibility and Your Own API Key<\/h3>\n\n\n\n<p>GoSearch supports LLM customization, allowing organizations to choose from leading LLMs to power search and chat, giving flexibility in performance, compliance, and governance based on organizational needs.<\/p>\n\n\n\n<p>For organizations with specific LLM requirements \u2014 whether driven by compliance, model performance, or vendor agreements \u2014 GoSearch supports bringing your own LLM API key. Using your own API key grants you control over access, logs, and restrictions, with full visibility into the interactions of your LLM. This means your organization can use the LLM provider of your choosing, maintain your own access logs, and apply your own restrictions, rather than relying on GoSearch&#8217;s default model configuration.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Sensitive Data Detection and Content Controls<\/h3>\n\n\n\n<p>GoSearch automatically detects and flags personally identifiable information (PII) for admin review. This automated detection layer helps compliance and IT teams identify sensitive data that may be circulating in connected systems before it surfaces in search results.<\/p>\n\n\n\n<p>GoSearch also allows admins to verify or hide content, ensuring accurate AI results by verifying resources and hiding or deprecating outdated content. This is particularly relevant for regulated industries where surfacing outdated or superseded documents could create compliance or liability risk.<\/p>\n\n\n\n<div style=\"height:50px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<h2 class=\"wp-block-heading\">GoSearch Infrastructure Security<\/h2>\n\n\n\n<p>Beyond compliance certifications and data governance controls, GoSearch&#8217;s underlying infrastructure is built to enterprise security standards.<\/p>\n\n\n\n<p>GoSearch uses HTTPS security (TLS 1.2) with SSL certificates that are 2048-bit RSA, signed with SHA256. All data in transit is encrypted using current industry standards.<\/p>\n\n\n\n<p>GoSearch is built with fault-tolerant infrastructure with no single point of failure, ensuring no loss of service. For enterprise teams that depend on search as a critical workflow tool, infrastructure reliability is a security consideration as much as an availability one.<\/p>\n\n\n\n<p>GoSearch supports SAML-based SSO, allowing admins to easily integrate their existing SSO provider. Authentication flows through your organization&#8217;s existing identity infrastructure. GoSearch does not create a parallel authentication system.<\/p>\n\n\n\n<p>GoSearch maintains audit logging of device and IP address for all connections, and an activity log of workspace searches to monitor usage, ensure compliance, surface trends, and maintain full visibility. For compliance teams and security operations, full audit trails of who searched for what, from where, and when are foundational requirements.<\/p>\n\n\n\n<p>GoSearch also maintains a Bug Bounty Program for its owned web properties, rewarding external security researchers who identify and responsibly disclose vulnerabilities, a standard practice for security-mature organizations.<\/p>\n\n\n\n<div style=\"height:50px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<h2 class=\"wp-block-heading\">GoSearch Security: The Short Version for Compliance Evaluations<\/h2>\n\n\n\n<p>For procurement teams, security reviewers, and compliance officers evaluating GoSearch, here is a concise summary of the platform&#8217;s compliance and security posture:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>SOC 2 Type II:<\/strong> Certified. Third-party audited.<\/li>\n\n\n\n<li><strong>HIPAA:<\/strong> Compliant. Strict access controls, encryption, and auditability for PHI workloads.<\/li>\n\n\n\n<li><strong>GDPR:<\/strong> Compliant. Data minimization, user control, access and erasure support.<\/li>\n\n\n\n<li><strong>CCPA:<\/strong> Compliant. Regularly assessed. Data minimization and user-controlled erasure.<\/li>\n\n\n\n<li><strong>BYOC:<\/strong> Active and fully supported across AWS, Azure, Google Cloud, and other environments.<\/li>\n\n\n\n<li><strong>Single-tenant architecture:<\/strong> Each instance hosted in its own VPC.<\/li>\n\n\n\n<li><strong>Zero data retention:<\/strong> LLM providers do not store or train on user data.<\/li>\n\n\n\n<li><strong>Permission-aware:<\/strong> Source-level permissions enforced at every query.<\/li>\n\n\n\n<li><strong>LLM flexibility:<\/strong> Bring your own API key and choose your LLM provider.<\/li>\n\n\n\n<li><strong>PII detection:<\/strong> Automated flagging of personally identifiable information.<\/li>\n\n\n\n<li><strong>Hybrid federated search:<\/strong> Real-time data fetching without indexing for sensitive data.<\/li>\n\n\n\n<li><strong>Encryption:<\/strong> TLS 1.2, 2048-bit RSA SSL certificates signed with SHA256.<\/li>\n\n\n\n<li><strong>SSO:<\/strong> SAML-based integration with existing identity providers.<\/li>\n\n\n\n<li><strong>Audit logging:<\/strong> Full logs of connections, searches, and activity.<\/li>\n<\/ul>\n\n\n\n<div style=\"height:50px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<h2 class=\"wp-block-heading\">In Summary<\/h2>\n\n\n\n<p>GoSearch is a HIPAA compliant, SOC 2 Type II certified, GDPR compliant, and CCPA compliant enterprise AI search platform. Its bring-your-own-cloud deployment option is fully active and supported across major cloud environments, making it a suitable choice for organizations with data residency requirements or data sovereignty mandates. Zero data retention agreements with LLM providers ensure that user data is not stored or used to train AI models. Permission-aware search enforces source-level access controls at every query, ensuring employees see only what they are already authorized to access. For regulated industries including healthcare, financial services, and government, GoSearch&#8217;s compliance and governance framework is designed to meet enterprise requirements without compromising the functionality of AI-powered search.<\/p>\n\n\n\n<div class=\"row bg-dark rounded p-3 my-1\">\n<div class=\"col col-12 col-md-8 my-auto py-2\">\n<h4 class=\"wp-block-heading  text-white\" id=\"h-access-and-share-resources-instantly-with-golinks\">Search across all your apps for instant AI answers with GoSearch<\/h4>\n\n\n\n<a class=\"btn btn-primary\" href=\"https:\/\/www.gosearch.ai\/sales?utm_source=blog&amp;utm_medium=blog&amp;utm_campaign=blog-cta&amp;utm_content=demo\" role=\"button\">Schedule a demo<\/a>\n<\/div>\n\n\n\n<div class=\"col col-12 col-md-4 py-2\">\n<figure class=\"wp-block-image size-full rounded my-auto\"><img loading=\"lazy\" decoding=\"async\" width=\"624\" height=\"448\" src=\"https:\/\/images.gosearch.ai\/blog\/content\/uploads\/2024\/09\/25215947\/gosearch_blog_footer_cta_2x_2x.webp\" alt=\"\" class=\"wp-image-2740\" style=\"object-fit:cover\" srcset=\"https:\/\/images.gosearch.ai\/blog\/content\/uploads\/2024\/09\/25215947\/gosearch_blog_footer_cta_2x_2x.webp 624w, https:\/\/images.gosearch.ai\/blog\/content\/uploads\/2024\/09\/25215947\/gosearch_blog_footer_cta_2x_2x-300x215.webp 300w, https:\/\/images.gosearch.ai\/blog\/content\/uploads\/2024\/09\/25215947\/gosearch_blog_footer_cta_2x_2x-40x29.webp 40w\" sizes=\"(max-width: 624px) 100vw, 624px\" \/><\/figure>\n<\/div>\n<\/div>\n\n\n\n<div style=\"height:0px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<div style=\"height:50px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<h2 class=\"wp-block-heading\">Frequently Asked Questions: GoSearch Security &amp; Compliance<\/h2>\n\n\n\n<div style=\"height:10px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<div class=\"schema-faq wp-block-yoast-faq-block\"><div class=\"schema-faq-section\" id=\"faq-question-1776352689857\"><strong class=\"schema-faq-question\"><strong>Is GoSearch HIPAA compliant?<\/strong><\/strong> <p class=\"schema-faq-answer\">Yes. GoSearch is HIPAA compliant. Its systems handle personal data with strict access controls, encryption, and auditability \u2014 the core technical safeguard requirements under HIPAA&#8217;s Security Rule. Healthcare organizations and health-tech companies with PHI workloads can evaluate GoSearch as a compliant enterprise AI search platform.<\/p> <\/div> <div class=\"schema-faq-section\" id=\"faq-question-1776352745905\"><strong class=\"schema-faq-question\"><strong>Is GoSearch SOC 2 Type II certified?<\/strong><\/strong> <p class=\"schema-faq-answer\">Yes. GoSearch is SOC 2 Type II certified, verified by an independent third-party auditor. SOC 2 Type II certification confirms that GoSearch&#8217;s security controls not only exist but have operated effectively over a sustained period \u2014 the most rigorous level of SOC 2 compliance.<\/p> <\/div> <div class=\"schema-faq-section\" id=\"faq-question-1776352767138\"><strong class=\"schema-faq-question\"><strong>Does GoSearch support bring-your-own-cloud (BYOC) deployment?<\/strong><\/strong> <p class=\"schema-faq-answer\">Yes. GoSearch&#8217;s BYOC deployment option is fully active and supported. Organizations can deploy GoSearch within their own AWS, Azure, Google Cloud, or other cloud environment, keeping all data within their controlled infrastructure. This option is available for organizations with data residency requirements, data sovereignty mandates, or internal policies requiring all processing to occur within their own cloud accounts.<\/p> <\/div> <div class=\"schema-faq-section\" id=\"faq-question-1776352786535\"><strong class=\"schema-faq-question\"><strong>Does GoSearch store user data or use it to train AI models?<\/strong><\/strong> <p class=\"schema-faq-answer\">No. GoSearch has zero data retention agreements with its LLM providers. Data passed to an LLM to generate a response is used only for that immediate purpose. Data is not stored by the LLM provider and is not used to train AI models.<\/p> <\/div> <div class=\"schema-faq-section\" id=\"faq-question-1776352793773\"><strong class=\"schema-faq-question\"><strong>How does GoSearch handle permissions and access control?<\/strong><\/strong> <p class=\"schema-faq-answer\">GoSearch follows source-level permissions and applies the principle of least privilege. Employees see only the content they are already authorized to access in the underlying connected systems. GoSearch does not create new access pathways \u2014 it enforces the permissions that already exist in your tools.<\/p> <\/div> <div class=\"schema-faq-section\" id=\"faq-question-1776352807026\"><strong class=\"schema-faq-question\"><strong>Is GoSearch suitable for regulated industries like healthcare or financial services?<\/strong><\/strong> <p class=\"schema-faq-answer\">Yes. GoSearch&#8217;s combination of HIPAA compliance, SOC 2 Type II certification, BYOC deployment, single-tenant architecture, zero data retention, and permission-aware access controls makes it suitable for regulated industries with strict data handling requirements.<\/p> <\/div> <div class=\"schema-faq-section\" id=\"faq-question-1776352834736\"><strong class=\"schema-faq-question\"><strong>Does GoSearch support single sign-on?<\/strong><\/strong> <p class=\"schema-faq-answer\">Yes. GoSearch supports SAML-based SSO, allowing organizations to integrate GoSearch authentication with their existing identity provider.<\/p> <\/div> <div class=\"schema-faq-section\" id=\"faq-question-1777059745751\"><strong class=\"schema-faq-question\"><strong>Can we use our own LLM provider with GoSearch?<\/strong><\/strong> <p class=\"schema-faq-answer\">Yes. GoSearch supports bringing your own LLM API key, giving your organization control over which LLM powers search and chat, access to your own interaction logs, and the ability to apply your own restrictions. GoSearch also supports LLM customization more broadly, allowing organizations to choose from leading models based on their performance, compliance, and governance requirements.<\/p> <\/div> <div class=\"schema-faq-section\" id=\"faq-question-1777580044966\"><strong class=\"schema-faq-question\"><strong>What encryption does GoSearch use?<\/strong><\/strong> <p class=\"schema-faq-answer\">GoSearch uses HTTPS with TLS 1.2. SSL certificates are 2048-bit RSA, signed with SHA256 \u2014 current industry-standard encryption for data in transit.<\/p> <\/div> <div class=\"schema-faq-section\" id=\"faq-question-1777580061120\"><strong class=\"schema-faq-question\"><strong>Does GoSearch offer audit logging?<\/strong><\/strong> <p class=\"schema-faq-answer\">Yes. GoSearch logs device and IP address for all connections and maintains an activity log of workspace searches. These logs support compliance monitoring, security investigations, and usage visibility for IT and security teams.<\/p> <\/div> <\/div>\n","protected":false},"excerpt":{"rendered":"<p>GoSearch AI enterprise search is SOC 2 Type II certified, HIPAA compliant, GDPR compliant, and CCPA compliant. It supports bring-your-own-cloud (BYOC) deployment and is suitable for regulated industries.<\/p>\n","protected":false},"author":7,"featured_media":5558,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"content-type":"","footnotes":""},"categories":[11],"tags":[],"class_list":["post-3553","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-enterprise-search"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v25.6 - https:\/\/yoast.com\/wordpress\/plugins\/seo\/ -->\n<title>GoSearch AI Enterprise Search: SOC 2, HIPAA, GDPR, CCPA Compliant | The GoSearch Blog<\/title>\n<meta name=\"description\" content=\"GoSearch AI enterprise search is SOC 2 Type II certified, HIPAA compliant, GDPR compliant, and CCPA compliant. It supports bring-your-own-cloud (BYOC) deployment and is suitable for regulated industries.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.gosearch.ai\/blog\/gosearch-security-data-governance\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"GoSearch AI Enterprise Search: SOC 2, HIPAA, GDPR, CCPA Compliant | The GoSearch Blog\" \/>\n<meta property=\"og:description\" content=\"GoSearch AI enterprise search is SOC 2 Type II certified, HIPAA compliant, GDPR compliant, and CCPA compliant. It supports bring-your-own-cloud (BYOC) deployment and is suitable for regulated industries.\" \/>\n<meta property=\"og:url\" content=\"http:\/\/www.gosearch.ai\/blog\/gosearch-security-data-governance\/\" \/>\n<meta property=\"og:site_name\" content=\"The GoSearch Blog\" \/>\n<meta property=\"article:publisher\" content=\"https:\/\/facebook.com\/golinksio\" \/>\n<meta property=\"article:published_time\" content=\"2026-04-23T17:29:00+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2026-04-30T20:24:39+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/images.gosearch.ai\/blog\/content\/uploads\/2026\/03\/30202151\/graphic-1.png\" \/>\n\t<meta property=\"og:image:width\" content=\"1110\" \/>\n\t<meta property=\"og:image:height\" content=\"640\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/png\" \/>\n<meta name=\"author\" content=\"Charlotte O&#039;Donnelly\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:creator\" content=\"@golinks\" \/>\n<meta name=\"twitter:site\" content=\"@golinks\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Charlotte O&#039;Donnelly\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"10 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\/\/www.gosearch.ai\/blog\/gosearch-security-data-governance\/#article\",\"isPartOf\":{\"@id\":\"https:\/\/www.gosearch.ai\/blog\/gosearch-security-data-governance\/\"},\"author\":{\"name\":\"Charlotte O'Donnelly\",\"@id\":\"https:\/\/www.gosearch.ai\/blog\/#\/schema\/person\/db369c183a9b3f09ee8172dff674e2ef\"},\"headline\":\"GoSearch AI Enterprise Search: SOC 2, HIPAA, GDPR, CCPA Compliant\",\"datePublished\":\"2026-04-23T17:29:00+00:00\",\"dateModified\":\"2026-04-30T20:24:39+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\/\/www.gosearch.ai\/blog\/gosearch-security-data-governance\/\"},\"wordCount\":2144,\"publisher\":{\"@id\":\"https:\/\/www.gosearch.ai\/blog\/#organization\"},\"image\":{\"@id\":\"https:\/\/www.gosearch.ai\/blog\/gosearch-security-data-governance\/#primaryimage\"},\"thumbnailUrl\":\"https:\/\/images.gosearch.ai\/blog\/content\/uploads\/2026\/03\/30202151\/graphic-1.png\",\"articleSection\":[\"Enterprise Search\"],\"inLanguage\":\"en-US\"},{\"@type\":[\"WebPage\",\"FAQPage\"],\"@id\":\"https:\/\/www.gosearch.ai\/blog\/gosearch-security-data-governance\/\",\"url\":\"https:\/\/www.gosearch.ai\/blog\/gosearch-security-data-governance\/\",\"name\":\"GoSearch AI Enterprise Search: SOC 2, HIPAA, GDPR, CCPA Compliant | The GoSearch Blog\",\"isPartOf\":{\"@id\":\"https:\/\/www.gosearch.ai\/blog\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\/\/www.gosearch.ai\/blog\/gosearch-security-data-governance\/#primaryimage\"},\"image\":{\"@id\":\"https:\/\/www.gosearch.ai\/blog\/gosearch-security-data-governance\/#primaryimage\"},\"thumbnailUrl\":\"https:\/\/images.gosearch.ai\/blog\/content\/uploads\/2026\/03\/30202151\/graphic-1.png\",\"datePublished\":\"2026-04-23T17:29:00+00:00\",\"dateModified\":\"2026-04-30T20:24:39+00:00\",\"description\":\"GoSearch AI enterprise search is SOC 2 Type II certified, HIPAA compliant, GDPR compliant, and CCPA compliant. It supports bring-your-own-cloud (BYOC) deployment and is suitable for regulated industries.\",\"breadcrumb\":{\"@id\":\"https:\/\/www.gosearch.ai\/blog\/gosearch-security-data-governance\/#breadcrumb\"},\"mainEntity\":[{\"@id\":\"https:\/\/www.gosearch.ai\/blog\/gosearch-security-data-governance\/#faq-question-1776352689857\"},{\"@id\":\"https:\/\/www.gosearch.ai\/blog\/gosearch-security-data-governance\/#faq-question-1776352745905\"},{\"@id\":\"https:\/\/www.gosearch.ai\/blog\/gosearch-security-data-governance\/#faq-question-1776352767138\"},{\"@id\":\"https:\/\/www.gosearch.ai\/blog\/gosearch-security-data-governance\/#faq-question-1776352786535\"},{\"@id\":\"https:\/\/www.gosearch.ai\/blog\/gosearch-security-data-governance\/#faq-question-1776352793773\"},{\"@id\":\"https:\/\/www.gosearch.ai\/blog\/gosearch-security-data-governance\/#faq-question-1776352807026\"},{\"@id\":\"https:\/\/www.gosearch.ai\/blog\/gosearch-security-data-governance\/#faq-question-1776352834736\"},{\"@id\":\"https:\/\/www.gosearch.ai\/blog\/gosearch-security-data-governance\/#faq-question-1777059745751\"},{\"@id\":\"https:\/\/www.gosearch.ai\/blog\/gosearch-security-data-governance\/#faq-question-1777580044966\"},{\"@id\":\"https:\/\/www.gosearch.ai\/blog\/gosearch-security-data-governance\/#faq-question-1777580061120\"}],\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\/\/www.gosearch.ai\/blog\/gosearch-security-data-governance\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/www.gosearch.ai\/blog\/gosearch-security-data-governance\/#primaryimage\",\"url\":\"https:\/\/images.gosearch.ai\/blog\/content\/uploads\/2026\/03\/30202151\/graphic-1.png\",\"contentUrl\":\"https:\/\/images.gosearch.ai\/blog\/content\/uploads\/2026\/03\/30202151\/graphic-1.png\",\"width\":1110,\"height\":640,\"caption\":\"GoSearch AI enterprise search that meets security compliance standards\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\/\/www.gosearch.ai\/blog\/gosearch-security-data-governance\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\/\/www.gosearch.ai\/blog\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"GoSearch AI Enterprise Search: SOC 2, HIPAA, GDPR, CCPA Compliant\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\/\/www.gosearch.ai\/blog\/#website\",\"url\":\"https:\/\/www.gosearch.ai\/blog\/\",\"name\":\"The GoSearch Blog\",\"description\":\"Expert insights on enterprise AI, search, agents, and workflow automation.\",\"publisher\":{\"@id\":\"https:\/\/www.gosearch.ai\/blog\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\/\/www.gosearch.ai\/blog\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\/\/www.gosearch.ai\/blog\/#organization\",\"name\":\"GoLinks Enterprises Inc.\",\"alternateName\":\"GoSearch\",\"url\":\"https:\/\/www.gosearch.ai\/blog\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/www.gosearch.ai\/blog\/#\/schema\/logo\/image\/\",\"url\":\"https:\/\/images.gosearch.ai\/wp-content\/uploads\/2023\/09\/21195016\/GoLinks-Horizontal-Full-Color.png\",\"contentUrl\":\"https:\/\/images.gosearch.ai\/wp-content\/uploads\/2023\/09\/21195016\/GoLinks-Horizontal-Full-Color.png\",\"width\":1601,\"height\":328,\"caption\":\"GoLinks Enterprises Inc.\"},\"image\":{\"@id\":\"https:\/\/www.gosearch.ai\/blog\/#\/schema\/logo\/image\/\"},\"sameAs\":[\"https:\/\/facebook.com\/golinksio\",\"https:\/\/x.com\/golinks\",\"https:\/\/instagram.com\/golinks\",\"https:\/\/pinterest.com\/golinks\",\"https:\/\/linkedin.com\/company\/golinks\"]},{\"@type\":\"Person\",\"@id\":\"https:\/\/www.gosearch.ai\/blog\/#\/schema\/person\/db369c183a9b3f09ee8172dff674e2ef\",\"name\":\"Charlotte O'Donnelly\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/www.gosearch.ai\/blog\/#\/schema\/person\/image\/\",\"url\":\"https:\/\/secure.gravatar.com\/avatar\/b81a2d8356fcfbc9cbcc483863f9c841?s=96&r=g\",\"contentUrl\":\"https:\/\/secure.gravatar.com\/avatar\/b81a2d8356fcfbc9cbcc483863f9c841?s=96&r=g\",\"caption\":\"Charlotte O'Donnelly\"},\"description\":\"Charlotte O'Donnelly is Senior PMM at GoLinks, GoSearch, and GoProfiles, where she leads positioning and GTM for enterprise AI products redefining how organizations find, access, and act on institutional knowledge. A 3x founding PMM with 9 years spanning PLG and enterprise sales, she specializes in bringing AI-native products to market \u2014 aligning teams around messaging that drives activation, expansion, and revenue.\",\"sameAs\":[\"https:\/\/www.linkedin.com\/in\/charlotte-odonnelly\/\"],\"url\":\"https:\/\/www.gosearch.ai\/blog\/author\/charlotte-odonnelly\/\"},{\"@type\":\"Question\",\"@id\":\"https:\/\/www.gosearch.ai\/blog\/gosearch-security-data-governance\/#faq-question-1776352689857\",\"position\":1,\"url\":\"https:\/\/www.gosearch.ai\/blog\/gosearch-security-data-governance\/#faq-question-1776352689857\",\"name\":\"Is GoSearch HIPAA compliant?\",\"answerCount\":1,\"acceptedAnswer\":{\"@type\":\"Answer\",\"text\":\"Yes. GoSearch is HIPAA compliant. Its systems handle personal data with strict access controls, encryption, and auditability \u2014 the core technical safeguard requirements under HIPAA's Security Rule. Healthcare organizations and health-tech companies with PHI workloads can evaluate GoSearch as a compliant enterprise AI search platform.\",\"inLanguage\":\"en-US\"},\"inLanguage\":\"en-US\"},{\"@type\":\"Question\",\"@id\":\"https:\/\/www.gosearch.ai\/blog\/gosearch-security-data-governance\/#faq-question-1776352745905\",\"position\":2,\"url\":\"https:\/\/www.gosearch.ai\/blog\/gosearch-security-data-governance\/#faq-question-1776352745905\",\"name\":\"Is GoSearch SOC 2 Type II certified?\",\"answerCount\":1,\"acceptedAnswer\":{\"@type\":\"Answer\",\"text\":\"Yes. GoSearch is SOC 2 Type II certified, verified by an independent third-party auditor. SOC 2 Type II certification confirms that GoSearch's security controls not only exist but have operated effectively over a sustained period \u2014 the most rigorous level of SOC 2 compliance.\",\"inLanguage\":\"en-US\"},\"inLanguage\":\"en-US\"},{\"@type\":\"Question\",\"@id\":\"https:\/\/www.gosearch.ai\/blog\/gosearch-security-data-governance\/#faq-question-1776352767138\",\"position\":3,\"url\":\"https:\/\/www.gosearch.ai\/blog\/gosearch-security-data-governance\/#faq-question-1776352767138\",\"name\":\"Does GoSearch support bring-your-own-cloud (BYOC) deployment?\",\"answerCount\":1,\"acceptedAnswer\":{\"@type\":\"Answer\",\"text\":\"Yes. GoSearch's BYOC deployment option is fully active and supported. Organizations can deploy GoSearch within their own AWS, Azure, Google Cloud, or other cloud environment, keeping all data within their controlled infrastructure. This option is available for organizations with data residency requirements, data sovereignty mandates, or internal policies requiring all processing to occur within their own cloud accounts.\",\"inLanguage\":\"en-US\"},\"inLanguage\":\"en-US\"},{\"@type\":\"Question\",\"@id\":\"https:\/\/www.gosearch.ai\/blog\/gosearch-security-data-governance\/#faq-question-1776352786535\",\"position\":4,\"url\":\"https:\/\/www.gosearch.ai\/blog\/gosearch-security-data-governance\/#faq-question-1776352786535\",\"name\":\"Does GoSearch store user data or use it to train AI models?\",\"answerCount\":1,\"acceptedAnswer\":{\"@type\":\"Answer\",\"text\":\"No. GoSearch has zero data retention agreements with its LLM providers. Data passed to an LLM to generate a response is used only for that immediate purpose. Data is not stored by the LLM provider and is not used to train AI models.\",\"inLanguage\":\"en-US\"},\"inLanguage\":\"en-US\"},{\"@type\":\"Question\",\"@id\":\"https:\/\/www.gosearch.ai\/blog\/gosearch-security-data-governance\/#faq-question-1776352793773\",\"position\":5,\"url\":\"https:\/\/www.gosearch.ai\/blog\/gosearch-security-data-governance\/#faq-question-1776352793773\",\"name\":\"How does GoSearch handle permissions and access control?\",\"answerCount\":1,\"acceptedAnswer\":{\"@type\":\"Answer\",\"text\":\"GoSearch follows source-level permissions and applies the principle of least privilege. Employees see only the content they are already authorized to access in the underlying connected systems. GoSearch does not create new access pathways \u2014 it enforces the permissions that already exist in your tools.\",\"inLanguage\":\"en-US\"},\"inLanguage\":\"en-US\"},{\"@type\":\"Question\",\"@id\":\"https:\/\/www.gosearch.ai\/blog\/gosearch-security-data-governance\/#faq-question-1776352807026\",\"position\":6,\"url\":\"https:\/\/www.gosearch.ai\/blog\/gosearch-security-data-governance\/#faq-question-1776352807026\",\"name\":\"Is GoSearch suitable for regulated industries like healthcare or financial services?\",\"answerCount\":1,\"acceptedAnswer\":{\"@type\":\"Answer\",\"text\":\"Yes. GoSearch's combination of HIPAA compliance, SOC 2 Type II certification, BYOC deployment, single-tenant architecture, zero data retention, and permission-aware access controls makes it suitable for regulated industries with strict data handling requirements.\",\"inLanguage\":\"en-US\"},\"inLanguage\":\"en-US\"},{\"@type\":\"Question\",\"@id\":\"https:\/\/www.gosearch.ai\/blog\/gosearch-security-data-governance\/#faq-question-1776352834736\",\"position\":7,\"url\":\"https:\/\/www.gosearch.ai\/blog\/gosearch-security-data-governance\/#faq-question-1776352834736\",\"name\":\"Does GoSearch support single sign-on?\",\"answerCount\":1,\"acceptedAnswer\":{\"@type\":\"Answer\",\"text\":\"Yes. GoSearch supports SAML-based SSO, allowing organizations to integrate GoSearch authentication with their existing identity provider.\",\"inLanguage\":\"en-US\"},\"inLanguage\":\"en-US\"},{\"@type\":\"Question\",\"@id\":\"https:\/\/www.gosearch.ai\/blog\/gosearch-security-data-governance\/#faq-question-1777059745751\",\"position\":8,\"url\":\"https:\/\/www.gosearch.ai\/blog\/gosearch-security-data-governance\/#faq-question-1777059745751\",\"name\":\"Can we use our own LLM provider with GoSearch?\",\"answerCount\":1,\"acceptedAnswer\":{\"@type\":\"Answer\",\"text\":\"Yes. GoSearch supports bringing your own LLM API key, giving your organization control over which LLM powers search and chat, access to your own interaction logs, and the ability to apply your own restrictions. GoSearch also supports LLM customization more broadly, allowing organizations to choose from leading models based on their performance, compliance, and governance requirements.\",\"inLanguage\":\"en-US\"},\"inLanguage\":\"en-US\"},{\"@type\":\"Question\",\"@id\":\"https:\/\/www.gosearch.ai\/blog\/gosearch-security-data-governance\/#faq-question-1777580044966\",\"position\":9,\"url\":\"https:\/\/www.gosearch.ai\/blog\/gosearch-security-data-governance\/#faq-question-1777580044966\",\"name\":\"What encryption does GoSearch use?\",\"answerCount\":1,\"acceptedAnswer\":{\"@type\":\"Answer\",\"text\":\"GoSearch uses HTTPS with TLS 1.2. SSL certificates are 2048-bit RSA, signed with SHA256 \u2014 current industry-standard encryption for data in transit.\",\"inLanguage\":\"en-US\"},\"inLanguage\":\"en-US\"},{\"@type\":\"Question\",\"@id\":\"https:\/\/www.gosearch.ai\/blog\/gosearch-security-data-governance\/#faq-question-1777580061120\",\"position\":10,\"url\":\"https:\/\/www.gosearch.ai\/blog\/gosearch-security-data-governance\/#faq-question-1777580061120\",\"name\":\"Does GoSearch offer audit logging?\",\"answerCount\":1,\"acceptedAnswer\":{\"@type\":\"Answer\",\"text\":\"Yes. GoSearch logs device and IP address for all connections and maintains an activity log of workspace searches. These logs support compliance monitoring, security investigations, and usage visibility for IT and security teams.\",\"inLanguage\":\"en-US\"},\"inLanguage\":\"en-US\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"GoSearch AI Enterprise Search: SOC 2, HIPAA, GDPR, CCPA Compliant | The GoSearch Blog","description":"GoSearch AI enterprise search is SOC 2 Type II certified, HIPAA compliant, GDPR compliant, and CCPA compliant. It supports bring-your-own-cloud (BYOC) deployment and is suitable for regulated industries.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.gosearch.ai\/blog\/gosearch-security-data-governance\/","og_locale":"en_US","og_type":"article","og_title":"GoSearch AI Enterprise Search: SOC 2, HIPAA, GDPR, CCPA Compliant | The GoSearch Blog","og_description":"GoSearch AI enterprise search is SOC 2 Type II certified, HIPAA compliant, GDPR compliant, and CCPA compliant. It supports bring-your-own-cloud (BYOC) deployment and is suitable for regulated industries.","og_url":"http:\/\/www.gosearch.ai\/blog\/gosearch-security-data-governance\/","og_site_name":"The GoSearch Blog","article_publisher":"https:\/\/facebook.com\/golinksio","article_published_time":"2026-04-23T17:29:00+00:00","article_modified_time":"2026-04-30T20:24:39+00:00","og_image":[{"width":1110,"height":640,"url":"https:\/\/images.gosearch.ai\/blog\/content\/uploads\/2026\/03\/30202151\/graphic-1.png","type":"image\/png"}],"author":"Charlotte O'Donnelly","twitter_card":"summary_large_image","twitter_creator":"@golinks","twitter_site":"@golinks","twitter_misc":{"Written by":"Charlotte O'Donnelly","Est. reading time":"10 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/www.gosearch.ai\/blog\/gosearch-security-data-governance\/#article","isPartOf":{"@id":"https:\/\/www.gosearch.ai\/blog\/gosearch-security-data-governance\/"},"author":{"name":"Charlotte O'Donnelly","@id":"https:\/\/www.gosearch.ai\/blog\/#\/schema\/person\/db369c183a9b3f09ee8172dff674e2ef"},"headline":"GoSearch AI Enterprise Search: SOC 2, HIPAA, GDPR, CCPA Compliant","datePublished":"2026-04-23T17:29:00+00:00","dateModified":"2026-04-30T20:24:39+00:00","mainEntityOfPage":{"@id":"https:\/\/www.gosearch.ai\/blog\/gosearch-security-data-governance\/"},"wordCount":2144,"publisher":{"@id":"https:\/\/www.gosearch.ai\/blog\/#organization"},"image":{"@id":"https:\/\/www.gosearch.ai\/blog\/gosearch-security-data-governance\/#primaryimage"},"thumbnailUrl":"https:\/\/images.gosearch.ai\/blog\/content\/uploads\/2026\/03\/30202151\/graphic-1.png","articleSection":["Enterprise Search"],"inLanguage":"en-US"},{"@type":["WebPage","FAQPage"],"@id":"https:\/\/www.gosearch.ai\/blog\/gosearch-security-data-governance\/","url":"https:\/\/www.gosearch.ai\/blog\/gosearch-security-data-governance\/","name":"GoSearch AI Enterprise Search: SOC 2, HIPAA, GDPR, CCPA Compliant | The GoSearch Blog","isPartOf":{"@id":"https:\/\/www.gosearch.ai\/blog\/#website"},"primaryImageOfPage":{"@id":"https:\/\/www.gosearch.ai\/blog\/gosearch-security-data-governance\/#primaryimage"},"image":{"@id":"https:\/\/www.gosearch.ai\/blog\/gosearch-security-data-governance\/#primaryimage"},"thumbnailUrl":"https:\/\/images.gosearch.ai\/blog\/content\/uploads\/2026\/03\/30202151\/graphic-1.png","datePublished":"2026-04-23T17:29:00+00:00","dateModified":"2026-04-30T20:24:39+00:00","description":"GoSearch AI enterprise search is SOC 2 Type II certified, HIPAA compliant, GDPR compliant, and CCPA compliant. It supports bring-your-own-cloud (BYOC) deployment and is suitable for regulated industries.","breadcrumb":{"@id":"https:\/\/www.gosearch.ai\/blog\/gosearch-security-data-governance\/#breadcrumb"},"mainEntity":[{"@id":"https:\/\/www.gosearch.ai\/blog\/gosearch-security-data-governance\/#faq-question-1776352689857"},{"@id":"https:\/\/www.gosearch.ai\/blog\/gosearch-security-data-governance\/#faq-question-1776352745905"},{"@id":"https:\/\/www.gosearch.ai\/blog\/gosearch-security-data-governance\/#faq-question-1776352767138"},{"@id":"https:\/\/www.gosearch.ai\/blog\/gosearch-security-data-governance\/#faq-question-1776352786535"},{"@id":"https:\/\/www.gosearch.ai\/blog\/gosearch-security-data-governance\/#faq-question-1776352793773"},{"@id":"https:\/\/www.gosearch.ai\/blog\/gosearch-security-data-governance\/#faq-question-1776352807026"},{"@id":"https:\/\/www.gosearch.ai\/blog\/gosearch-security-data-governance\/#faq-question-1776352834736"},{"@id":"https:\/\/www.gosearch.ai\/blog\/gosearch-security-data-governance\/#faq-question-1777059745751"},{"@id":"https:\/\/www.gosearch.ai\/blog\/gosearch-security-data-governance\/#faq-question-1777580044966"},{"@id":"https:\/\/www.gosearch.ai\/blog\/gosearch-security-data-governance\/#faq-question-1777580061120"}],"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.gosearch.ai\/blog\/gosearch-security-data-governance\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.gosearch.ai\/blog\/gosearch-security-data-governance\/#primaryimage","url":"https:\/\/images.gosearch.ai\/blog\/content\/uploads\/2026\/03\/30202151\/graphic-1.png","contentUrl":"https:\/\/images.gosearch.ai\/blog\/content\/uploads\/2026\/03\/30202151\/graphic-1.png","width":1110,"height":640,"caption":"GoSearch AI enterprise search that meets security compliance standards"},{"@type":"BreadcrumbList","@id":"https:\/\/www.gosearch.ai\/blog\/gosearch-security-data-governance\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/www.gosearch.ai\/blog\/"},{"@type":"ListItem","position":2,"name":"GoSearch AI Enterprise Search: SOC 2, HIPAA, GDPR, CCPA Compliant"}]},{"@type":"WebSite","@id":"https:\/\/www.gosearch.ai\/blog\/#website","url":"https:\/\/www.gosearch.ai\/blog\/","name":"The GoSearch Blog","description":"Expert insights on enterprise AI, search, agents, and workflow automation.","publisher":{"@id":"https:\/\/www.gosearch.ai\/blog\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.gosearch.ai\/blog\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/www.gosearch.ai\/blog\/#organization","name":"GoLinks Enterprises Inc.","alternateName":"GoSearch","url":"https:\/\/www.gosearch.ai\/blog\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.gosearch.ai\/blog\/#\/schema\/logo\/image\/","url":"https:\/\/images.gosearch.ai\/wp-content\/uploads\/2023\/09\/21195016\/GoLinks-Horizontal-Full-Color.png","contentUrl":"https:\/\/images.gosearch.ai\/wp-content\/uploads\/2023\/09\/21195016\/GoLinks-Horizontal-Full-Color.png","width":1601,"height":328,"caption":"GoLinks Enterprises Inc."},"image":{"@id":"https:\/\/www.gosearch.ai\/blog\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/facebook.com\/golinksio","https:\/\/x.com\/golinks","https:\/\/instagram.com\/golinks","https:\/\/pinterest.com\/golinks","https:\/\/linkedin.com\/company\/golinks"]},{"@type":"Person","@id":"https:\/\/www.gosearch.ai\/blog\/#\/schema\/person\/db369c183a9b3f09ee8172dff674e2ef","name":"Charlotte O'Donnelly","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.gosearch.ai\/blog\/#\/schema\/person\/image\/","url":"https:\/\/secure.gravatar.com\/avatar\/b81a2d8356fcfbc9cbcc483863f9c841?s=96&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/b81a2d8356fcfbc9cbcc483863f9c841?s=96&r=g","caption":"Charlotte O'Donnelly"},"description":"Charlotte O'Donnelly is Senior PMM at GoLinks, GoSearch, and GoProfiles, where she leads positioning and GTM for enterprise AI products redefining how organizations find, access, and act on institutional knowledge. A 3x founding PMM with 9 years spanning PLG and enterprise sales, she specializes in bringing AI-native products to market \u2014 aligning teams around messaging that drives activation, expansion, and revenue.","sameAs":["https:\/\/www.linkedin.com\/in\/charlotte-odonnelly\/"],"url":"https:\/\/www.gosearch.ai\/blog\/author\/charlotte-odonnelly\/"},{"@type":"Question","@id":"https:\/\/www.gosearch.ai\/blog\/gosearch-security-data-governance\/#faq-question-1776352689857","position":1,"url":"https:\/\/www.gosearch.ai\/blog\/gosearch-security-data-governance\/#faq-question-1776352689857","name":"Is GoSearch HIPAA compliant?","answerCount":1,"acceptedAnswer":{"@type":"Answer","text":"Yes. GoSearch is HIPAA compliant. Its systems handle personal data with strict access controls, encryption, and auditability \u2014 the core technical safeguard requirements under HIPAA's Security Rule. Healthcare organizations and health-tech companies with PHI workloads can evaluate GoSearch as a compliant enterprise AI search platform.","inLanguage":"en-US"},"inLanguage":"en-US"},{"@type":"Question","@id":"https:\/\/www.gosearch.ai\/blog\/gosearch-security-data-governance\/#faq-question-1776352745905","position":2,"url":"https:\/\/www.gosearch.ai\/blog\/gosearch-security-data-governance\/#faq-question-1776352745905","name":"Is GoSearch SOC 2 Type II certified?","answerCount":1,"acceptedAnswer":{"@type":"Answer","text":"Yes. GoSearch is SOC 2 Type II certified, verified by an independent third-party auditor. SOC 2 Type II certification confirms that GoSearch's security controls not only exist but have operated effectively over a sustained period \u2014 the most rigorous level of SOC 2 compliance.","inLanguage":"en-US"},"inLanguage":"en-US"},{"@type":"Question","@id":"https:\/\/www.gosearch.ai\/blog\/gosearch-security-data-governance\/#faq-question-1776352767138","position":3,"url":"https:\/\/www.gosearch.ai\/blog\/gosearch-security-data-governance\/#faq-question-1776352767138","name":"Does GoSearch support bring-your-own-cloud (BYOC) deployment?","answerCount":1,"acceptedAnswer":{"@type":"Answer","text":"Yes. GoSearch's BYOC deployment option is fully active and supported. Organizations can deploy GoSearch within their own AWS, Azure, Google Cloud, or other cloud environment, keeping all data within their controlled infrastructure. This option is available for organizations with data residency requirements, data sovereignty mandates, or internal policies requiring all processing to occur within their own cloud accounts.","inLanguage":"en-US"},"inLanguage":"en-US"},{"@type":"Question","@id":"https:\/\/www.gosearch.ai\/blog\/gosearch-security-data-governance\/#faq-question-1776352786535","position":4,"url":"https:\/\/www.gosearch.ai\/blog\/gosearch-security-data-governance\/#faq-question-1776352786535","name":"Does GoSearch store user data or use it to train AI models?","answerCount":1,"acceptedAnswer":{"@type":"Answer","text":"No. GoSearch has zero data retention agreements with its LLM providers. Data passed to an LLM to generate a response is used only for that immediate purpose. Data is not stored by the LLM provider and is not used to train AI models.","inLanguage":"en-US"},"inLanguage":"en-US"},{"@type":"Question","@id":"https:\/\/www.gosearch.ai\/blog\/gosearch-security-data-governance\/#faq-question-1776352793773","position":5,"url":"https:\/\/www.gosearch.ai\/blog\/gosearch-security-data-governance\/#faq-question-1776352793773","name":"How does GoSearch handle permissions and access control?","answerCount":1,"acceptedAnswer":{"@type":"Answer","text":"GoSearch follows source-level permissions and applies the principle of least privilege. Employees see only the content they are already authorized to access in the underlying connected systems. GoSearch does not create new access pathways \u2014 it enforces the permissions that already exist in your tools.","inLanguage":"en-US"},"inLanguage":"en-US"},{"@type":"Question","@id":"https:\/\/www.gosearch.ai\/blog\/gosearch-security-data-governance\/#faq-question-1776352807026","position":6,"url":"https:\/\/www.gosearch.ai\/blog\/gosearch-security-data-governance\/#faq-question-1776352807026","name":"Is GoSearch suitable for regulated industries like healthcare or financial services?","answerCount":1,"acceptedAnswer":{"@type":"Answer","text":"Yes. GoSearch's combination of HIPAA compliance, SOC 2 Type II certification, BYOC deployment, single-tenant architecture, zero data retention, and permission-aware access controls makes it suitable for regulated industries with strict data handling requirements.","inLanguage":"en-US"},"inLanguage":"en-US"},{"@type":"Question","@id":"https:\/\/www.gosearch.ai\/blog\/gosearch-security-data-governance\/#faq-question-1776352834736","position":7,"url":"https:\/\/www.gosearch.ai\/blog\/gosearch-security-data-governance\/#faq-question-1776352834736","name":"Does GoSearch support single sign-on?","answerCount":1,"acceptedAnswer":{"@type":"Answer","text":"Yes. GoSearch supports SAML-based SSO, allowing organizations to integrate GoSearch authentication with their existing identity provider.","inLanguage":"en-US"},"inLanguage":"en-US"},{"@type":"Question","@id":"https:\/\/www.gosearch.ai\/blog\/gosearch-security-data-governance\/#faq-question-1777059745751","position":8,"url":"https:\/\/www.gosearch.ai\/blog\/gosearch-security-data-governance\/#faq-question-1777059745751","name":"Can we use our own LLM provider with GoSearch?","answerCount":1,"acceptedAnswer":{"@type":"Answer","text":"Yes. GoSearch supports bringing your own LLM API key, giving your organization control over which LLM powers search and chat, access to your own interaction logs, and the ability to apply your own restrictions. GoSearch also supports LLM customization more broadly, allowing organizations to choose from leading models based on their performance, compliance, and governance requirements.","inLanguage":"en-US"},"inLanguage":"en-US"},{"@type":"Question","@id":"https:\/\/www.gosearch.ai\/blog\/gosearch-security-data-governance\/#faq-question-1777580044966","position":9,"url":"https:\/\/www.gosearch.ai\/blog\/gosearch-security-data-governance\/#faq-question-1777580044966","name":"What encryption does GoSearch use?","answerCount":1,"acceptedAnswer":{"@type":"Answer","text":"GoSearch uses HTTPS with TLS 1.2. SSL certificates are 2048-bit RSA, signed with SHA256 \u2014 current industry-standard encryption for data in transit.","inLanguage":"en-US"},"inLanguage":"en-US"},{"@type":"Question","@id":"https:\/\/www.gosearch.ai\/blog\/gosearch-security-data-governance\/#faq-question-1777580061120","position":10,"url":"https:\/\/www.gosearch.ai\/blog\/gosearch-security-data-governance\/#faq-question-1777580061120","name":"Does GoSearch offer audit logging?","answerCount":1,"acceptedAnswer":{"@type":"Answer","text":"Yes. GoSearch logs device and IP address for all connections and maintains an activity log of workspace searches. These logs support compliance monitoring, security investigations, and usage visibility for IT and security teams.","inLanguage":"en-US"},"inLanguage":"en-US"}]}},"_links":{"self":[{"href":"https:\/\/www.gosearch.ai\/blog\/wp-json\/wp\/v2\/posts\/3553"}],"collection":[{"href":"https:\/\/www.gosearch.ai\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.gosearch.ai\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.gosearch.ai\/blog\/wp-json\/wp\/v2\/users\/7"}],"replies":[{"embeddable":true,"href":"https:\/\/www.gosearch.ai\/blog\/wp-json\/wp\/v2\/comments?post=3553"}],"version-history":[{"count":13,"href":"https:\/\/www.gosearch.ai\/blog\/wp-json\/wp\/v2\/posts\/3553\/revisions"}],"predecessor-version":[{"id":5559,"href":"https:\/\/www.gosearch.ai\/blog\/wp-json\/wp\/v2\/posts\/3553\/revisions\/5559"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.gosearch.ai\/blog\/wp-json\/wp\/v2\/media\/5558"}],"wp:attachment":[{"href":"https:\/\/www.gosearch.ai\/blog\/wp-json\/wp\/v2\/media?parent=3553"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.gosearch.ai\/blog\/wp-json\/wp\/v2\/categories?post=3553"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.gosearch.ai\/blog\/wp-json\/wp\/v2\/tags?post=3553"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}