Trust & Security

Security is part of the engagement.

How we protect the information our clients — including government agencies — entrust to us. Last updated July 2026.

At a glance

Four commitments behind every engagement.

01

US data at rest

All client and program data is stored exclusively in the United States, including backups.

02

Encrypted everywhere

TLS 1.2+ in transit with HSTS; AES-256 at rest. HTTPS-only, always.

03

Least privilege, logged

Row-level security on every table, database-enforced admin rights, and an append-only audit trail.

04

Built for public sector

Certified NYC & NY State M/WBE with a written security program aligned to the NY SHIELD Act and NYC vendor standards.

The controls

How we protect your data.

01

Infrastructure & hosting

Our platform runs on enterprise-grade cloud infrastructure: the application is served from Cloudflare's global edge network, and data is stored in a managed PostgreSQL database hosted by Supabase in the United States. Both providers maintain independently audited security programs (SOC 2 Type II and ISO 27001), undergo continuous monitoring, and provide DDoS protection, network isolation, and managed patching.

02

Encryption

All data is encrypted in transit using TLS 1.2 or higher — connections are HTTPS-only, enforced with HTTP Strict Transport Security. Data at rest, including database storage and backups, is encrypted with AES-256. Session cookies are encrypted, signed, and scoped with httpOnly and secure flags.

03

Access control

Access to data follows the principle of least privilege. Every database table is protected by row-level security policies, and administrative privileges are granted only through database-enforced allowlists — application code cannot self-escalate. Administrative and participant access to sensitive records is recorded in an append-only audit log, and login endpoints are rate-limited with lockout protections against brute-force attempts.

04

Data handling & residency

All client and program data is stored at rest exclusively in the United States, including backups. Requests are served through our edge provider's global network, where processing is transient and in-memory only — no data is persisted outside the US, and regional processing restrictions are available where an engagement requires them. We collect only the information needed to deliver our services, retain it only as long as required by the engagement and applicable law, and dispose of it securely. Program-specific data handled for government engagements is segregated, access-restricted, and handled per the contracting agency's data requirements.

Subprocessors

A small set of vetted providers.

Each is bound by data-protection obligations, maintains its own audited security program, and receives only the minimum data necessary. We review this list before adding any provider.

ProviderPurposeAssurance
CloudflareEdge hosting, DDoS protection, TLSSOC 2 / ISO 27001
SupabaseDatabase & authentication (US region)SOC 2 Type II
LovableApplication platform & transactional emailUS-hosted
PostHog (US Cloud)Product analytics — marketing pages onlySOC 2
GoogleSite analytics — marketing pages onlyISO 27001
CalendlyScheduling embeds on booking pagesSOC 2

Our site concierge is powered by Google Gemini via the Lovable AI gateway and receives visitor questions only — no account or program data. Analytics and the concierge are excluded entirely from government-program pages.

Compliance

Commitments we put in writing.

  • A written information-security program with administrative, technical, and physical safeguards consistent with the New York SHIELD Act.
  • Alignment with the Citywide Cybersecurity Policies and Standards published by the NYC Office of Technology and Innovation.
  • Acknowledgment of agency user-responsibility and privacy policies for every person assigned to a City engagement.
  • Full cooperation with NYC Cyber Command security reviews and monitoring for the engagements we serve.
  • Certified NYC and NY State Minority/Women-owned Business Enterprise (M/WBE).
If something goes wrong

Incident response, in plain terms.

We maintain a documented incident-response plan with defined roles, severity levels, and escalation paths. In the event of a security incident affecting personal information, we will notify affected individuals and regulators as required by the NY SHIELD Act and New York breach-notification law, and notify contracting agencies in accordance with our agreements — promptly and transparently.

Recovery is rehearsed, not improvised: the plan pairs with tested runbooks for restoration and continuity, backed by point-in-time database recovery.

Vulnerability disclosure

Found something? Tell us.

We welcome good-faith security research. We commit to acknowledging reports promptly, keeping researchers informed, and not pursuing legal action against good-faith research conducted without harm to our users or data. Our machine-readable policy lives at /.well-known/security.txt.

Last updated · July 2026