The Public Service Platform for modern government
One unified platform powering every product, connecting every department, serving every resident.
Explore success stories by region, department, and platform
Lauderdale Lakes is a close-knit, diverse city driven by care. Its permitting transformati…
Read more
In a town known more for college football than technology, Starkville’s Planning Departmen…
Read more
In Eufaula, Alabama, leadership didn’t wait for change. They made it happen. Now, their wa…
Read moreExplore success stories by region, department, and platform
Lauderdale Lakes is a close-knit, diverse city driven by care. Its permitting transformati…
Read more
In a town known more for college football than technology, Starkville’s Planning Departmen…
Read more
In Eufaula, Alabama, leadership didn’t wait for change. They made it happen. Now, their wa…
Read moreSecurity-first cloud platform
The security and reliability of our platform — and the data entrusted to it — is our highest priority. Our program follows the NIST Cybersecurity Framework (CSF) and is regularly validated through independent audits and security assessments.
Dive into the areas that matter most for your security evaluation.
AWS hosting, encryption standards, network isolation, data protection, and high-availability design across our cloud platform.
Learn more→Our responsible disclosure policy for security researchers, including reporting guidelines, safe harbor provisions, and expectations.
View policy→Published advisories about identified and remediated vulnerabilities in OpenGov products and services.
View advisories→Looking for compliance certifications, privacy documentation, or data processing agreements?
Visit the OpenGov Trust CenterOpenGov's cloud platform is built on AWS with defense-in-depth security across every layer — from physical data centers to application containers.
The OpenGov Cloud platform is provisioned in the US East (Northern Virginia) Region of AWS, utilizing multiple Availability Zones interconnected with low-latency, highly-redundant networking. Pre-production environments are geo-isolated in the US West (Oregon) Region.
OpenGov personnel do not have physical access to data centers. Physical and environmental controls are inherited from AWS's FedRAMP-authorized infrastructure. OpenGov's application layer operates under its own SOC 2 Type II program.
Customer data is protected by TLS 1.2+ in transit. Cloudflare serves as the web application firewall, providing an additional defense layer against threats.
Databases use a multi-AZ deployment strategy for enhanced availability and durability. Regular backups and snapshots are stored across regional data centers. Real-time replication across AWS availability zones limits potential data loss to under one minute in a failover scenario.
OpenGov maintains documented RTO/RPO objectives for all production systems. Our infrastructure meets a 4-hour RPO through real-time, multi-AZ database replication and 24-hour RTO via automated failover across Availability Zones. Recovery objectives are validated through regular backup and restoration testing, with results reviewed by security and reported to leadership.
OpenGov performs regular backup integrity and restoration testing to validate recoverability. Automated backups run continuously; restoration tests confirm data integrity and RTO/RPO targets. Results are documented and reviewed during annual SOC 2 audits.
OpenGov uses FIPS 140-2 validated cryptographic modules inherited from AWS and Microsoft Azure cloud providers. Both AWS KMS and Azure Key Vault provide FIPS 140-2 validated encryption for OpenGov's data at rest and in transit.
An industry-leading Intrusion Detection Service (IDS) provides continuous monitoring across vulnerability detection, file integrity monitoring, configuration auditing, and threat correlation.
AWS Virtual Private Cloud (VPC) technology isolates compute instances and resources. Security Groups provide virtual firewall controls for traffic management. DDoS protection leverages AWS Shield, and pre-production assets are accessible only via VPN.
Remote access to production systems is strictly limited to Engineering personnel on a time-bound, approved-business-case basis. Perpetual administrative access is prohibited. All access is fully audited, and multi-factor authentication (MFA) is required. AWS IAM provides fine-grained access control.
Application services run in isolated namespaces and containers with strict resource limits, preventing cross-service impact. Minimum replica counts ensure high availability.
Continuous Integration pipelines and vulnerability analysis services scan applications automatically at every lifecycle stage. Code repositories are continuously scanned for known defects, and compiled artifacts are re-scanned before distribution. An independent third-party penetration test is conducted at least annually.
A comprehensive suite of industry-standard services covers availability, performance, security, logging, and metrics. OpenGov partners with a reputable managed security service provider for enhanced threat detection and incident response, with operational teams on standby 24/7.
OpenGov provides centralized identity and authentication support across its cloud platform. For governments that wish to leverage their own Enterprise Identity Provider (IdP), OpenGov supports integration with any SAML 2.0 compliant IdP, including both IdP-initiated and SP-initiated authentication flows.
Platform updates are performed without causing downtime, generally every two weeks during off-business hours. Feature flags enable controlled rollout, and services are deployed and rolled back individually to isolate potential issues.
Releases are executed through automated pipelines under the supervision of trained release managers who enforce change management discipline. Customers can subscribe to maintenance and incident notifications through the Help Center.
OpenGov uses open-source software (OSS) libraries, packages, and frameworks as part of our products and services. OSS components are reviewed to ensure license compliance and to verify no adverse impact on OpenGov intellectual property. Copyright notices for specific packages are available upon request to moc.v1786048031ognep1786048031o@lag1786048031el1786048031.
OpenGov's Global Security Team is responsible for the strategy, compliance, and operational monitoring of our environment, partnering with an industry-leading managed security service provider for 24/7 detection and monitoring.
Our security strategy is grounded in the NIST Cybersecurity Framework. Policies and procedures are based on NIST 800-53 controls and audited annually for SOC 2 compliance. All personnel complete comprehensive security and data privacy training upon joining and at least annually. A robust phishing assessment program keeps team members aware of prevailing threats.
OpenGov is an accredited technology partner in the AWS Government Competency Program, recognized for technical proficiency and proven customer success in delivering mission-critical workloads. OpenGov undergoes an in-depth capability review by AWS every 12 months covering solution architecture and security.
OpenGov values the security research community and welcomes collaboration to make our products and services more secure.
OpenGov believes that the disclosure of vulnerabilities is essential to improving the quality of our products and services. OpenGov values the insights of the security research community and welcomes disclosure and collaboration.
Through our responsible disclosure process OpenGov will work with security researchers and other vulnerability investigators to make our products and services more secure by providing a mechanism to privately report vulnerabilities with legitimacy and integrity. Responsible disclosure ensures that security infrastructure is tested and proven reliable. This process allows us to work collaboratively with the researchers to identify and mitigate vulnerabilities quickly in an ever-changing security environment.
We are committed to working collaboratively with security researchers and will respond to all valid submissions within the following timelines:
| Milestone | Target |
|---|---|
| Acknowledgment of receipt | Within 3 business days |
| Initial triage and severity assessment | Within 10 business days |
| Status updates on open findings | Every 30 days until resolved |
| Critical/High severity remediation target | 30 days from triage |
| Medium severity remediation target | 90 days from triage |
| Low / Informational remediation target | Best effort |
Timelines may vary based on issue complexity. We will communicate any delays proactively.
The following systems and assets are within scope for vulnerability disclosure:
The following are explicitly out of scope and should not be tested:
To report a vulnerability, please send an email to moc.v1786048031ognep1786048031o@yti1786048031ruces1786048031 with the following information:
OpenGov will follow standard industry practices for coordinated and responsible vulnerability disclosure. We ask all vulnerability reporters to do the same by allowing OpenGov the opportunity to verify and remediate reported vulnerabilities and for us to notify our affected customers and users before you disclose or share the vulnerability or methods to exploit with any third party.
OpenGov product security advisories will be made publicly available at https://trust.opengov.com.
OpenGov believes that ethical security research performed in good-faith provides an invaluable public service and has therefore provided this safe harbor program to encourage lawful, authorized security testing of our products and services. Accordingly, OpenGov will not initiate, pursue or recommend any law enforcement or civil lawsuits related to the specific actions taken by you to discover a security vulnerability, provided that such actions were undertaken consistent with this policy and in good faith, for the sole purpose of improving the overall security of our products and services, and not for any nefarious or otherwise unlawful purpose. OpenGov will not pursue civil action or refer researchers to law enforcement for security research conducted in good faith and in compliance with this policy.
You are, however, otherwise expected to comply with all applicable laws. If we become aware that government authorities have initiated legal action against you for security research conducted in strict accordance with the terms of this policy, we will advise the applicable government authorities that we consider your actions to have been "authorized" hereunder.
Please note that this safe-harbor policy will not apply to security activities performed in accordance with an executed, written agreement between you and OpenGov, and the terms of any such agreement shall prevail in their entirety over the terms of this policy, which shall not apply in such cases.
If at any time you have concerns or are uncertain whether your security research is consistent with this policy, please inquire via moc.v1786048031ognep1786048031o@yti1786048031ruces1786048031 before going any further.
OpenGov publishes advisories about identified and remediated security vulnerabilities through our Trust Center — the authoritative source for live security updates.
OpenGov publishes advisories for security vulnerabilities that affect our platform and are relevant to our customers. Advisories include details on the affected component, severity rating, and remediation status.
Live advisories are maintained at our Trust Center: trust.opengov.com
Advisories are issued when:
To receive advisory notifications, subscribe via the OpenGov Trust Center.
To report a vulnerability, see our Vulnerability Disclosure Policy.
Our Trust Center provides real-time security advisories, compliance documentation, and status updates for all OpenGov products and services.
Visit Trust CenterTo receive notifications about new security advisories, subscribe to updates at the Trust Center.
Found a potential security issue? Read our Responsible Disclosure Policy for reporting guidelines, safe harbor provisions, and what to expect.
Contact our Security Team at moc.v1786048031ognep1786048031o@yti1786048031ruces1786048031 for additional information, to report vulnerabilities, or for any concerns related to the security of the OpenGov platform.
Log in to Products

Permitting & Licensing
Permit workflows, online payments, and public portal

Procurement & Contract Management
Full lifecycle procurement automation

Tax & Revenue Collection
Tax billing and collection software for all revenue types
Log in to Resources
Have trouble logging in? Contact Support
Log in with Permitting & Licensing Subdomain
Replace “organization” with your organization’s login.
Log in to other Products

Tax & Revenue Collection
Log in with Tax & Revenue Collection Subdomain
Replace “organization” with your organization’s login.
Log in to other Products

Permitting & Licensing
Choose your login type to continue