The EU-US Data Privacy Framework, explained for vendor reviews
Solomon Amos · 7 Sep 2026 · 10 min read
Regulatory evidence
A learning platform that enables you to train your staff or customers.
For each regulation, how many of the requirements it places on your vendors Go1’s public evidence reaches. Open one for every item with its date and source.
What the vendor lists, typed; public items can be read now, the rest are available on request.
13 documents listed on Go1’s trust centre
trust.go1.comAnswers the vendor publishes to questions buyers ask, quoted with the link to where it says so.
Where data is hosted or processed
Where is our data hosted and Is it possible to store PII in a specific geographic/geopolitical region?
“Go1’s core production platform is hosted primarily on Amazon Web Services (AWS). The primary AWS regions supporting the platform are Australia ( ap-southeast-2 ), the European Union ( eu-west-1 ), and the United States ( us-east-2 ). Customers can select a primary region for data localisation where supported. Certain limited supporting workloads continue to operate in Microsoft Azure. Some services may operate acr...”
Regions named: EU, US, Australiaas of 21 Sep 2026Source
Encryption
Can we encrypt our data in the Go1 platform with our own encryption key?
“No, currently Go1 does not support BYOK (Bring Your Own Key).”
as of 21 Sep 2026Source
Encryption
Do you encrypt data at rest?
“Yes, all data (including backups) are encrypted at rest using AES256.”
as of 21 Sep 2026Source
Encryption
Do you encrypt data in transit?
“Yes, all data is encrypted in transit using TLS 1.2 or 1.3.”
as of 21 Sep 2026Source
Incident and breach notification
Do you notify customers of security incidents that may affect them?
“Yes, we aim to notify customers within 24 hours of becoming aware of a security incident that may impact our customers.”
as of 21 Sep 2026Source
Penetration testing
Have all the findings in the 2024 Penetration Test been mitigated?
“Yes, all findings from the 2024 Penetration Test (Web Applications & API Pentest) have been mitigated.”
as of 21 Sep 2026Source
Solomon Amos · 7 Sep 2026 · 10 min read
CertReports Research · 18 Sep 2026 · 12 min read
This maps third-party obligations to the vendor evidence that may support them. It is not legal advice and never a statement that a vendor or its customers comply; confirm scope and sufficiency with your counsel or auditor. “No public evidence” means nothing public was found at the last check. Citations link to the official text.