Our approach

Security is built into the operating model.

Our security protocol constantly evolves to stay ahead of threats and keep agency data secure from server to end user. The platform is built to meet or exceed local, state, and federal authentication expectations.

Security overview (PDF)

Encrypted end to end

Data is encrypted in transit and at rest, across desktop, mobile, server, and cloud infrastructure.

Access by role

Security controls are designed around appropriate access, protected credentials, and auditable operations.

Cloud-hosted in the US

Hosted on Azure and AWS US infrastructure, with a posture built for public-sector and regulated workloads.

Our posture

Audited, approved, and ready for regulated work.

Compliance signals should be easy to verify. These are the core markers customers ask us about most often.

Audited

SOC 2 Type II

Independent attestation of controls and operating effectiveness.

GovRAMP Member

Aligned with the state and local government counterpart to FedRAMP.

WA State OCIO Approved

Approved for Washington State government use.

HIPAA + BAA

Supported for regulated registry and healthcare-adjacent workloads.

Encrypted data

Data protection in transit and at rest is part of the operating baseline.

Azure / AWS (US)

Hosted on established US cloud infrastructure for resilient operations.