Security-first cloud platform

Security at OpenGov

The security and reliability of our platform — and the data entrusted to it — is our highest priority. Our program follows the NIST Cybersecurity Framework (CSF) and is regularly validated through independent audits and security assessments.

SOC 2 Type II
Security, Availability, Processing Integrity & Confidentiality
AES-256
Encryption at Rest
TLS 1.2+
Encryption in Transit
NIST
CSF 2.0 Framework · 800-53 Rev. 5 Policies & Controls

Infrastructure & Architecture

OpenGov's cloud platform is built on AWS with defense-in-depth security across every layer — from physical data centers to application containers.

Physical & Environmental

The OpenGov Cloud platform is provisioned in the US East (Northern Virginia) Region of AWS, utilizing multiple Availability Zones interconnected with low-latency, highly-redundant networking. Pre-production environments are geo-isolated in the US West (Oregon) Region.

OpenGov personnel do not have physical access to data centers. Physical and environmental controls are inherited from AWS's FedRAMP-authorized infrastructure. OpenGov's application layer operates under its own SOC 2 Type II program.

Data Protection

Customer data is protected by TLS 1.2+ in transit. Cloudflare serves as the web application firewall, providing an additional defense layer against threats.

Databases use a multi-AZ deployment strategy for enhanced availability and durability. Regular backups and snapshots are stored across regional data centers. Real-time replication across AWS availability zones limits potential data loss to under one minute in a failover scenario.

Recovery Objectives

OpenGov maintains documented RTO/RPO objectives for all production systems. Our infrastructure meets a 4-hour RPO through real-time, multi-AZ database replication and 24-hour RTO via automated failover across Availability Zones. Recovery objectives are validated through regular backup and restoration testing, with results reviewed by security and reported to leadership.

Backup and Restoration Testing

OpenGov performs regular backup integrity and restoration testing to validate recoverability. Automated backups run continuously; restoration tests confirm data integrity and RTO/RPO targets. Results are documented and reviewed during annual SOC 2 audits.

FIPS 140-2 Validated Cryptography

OpenGov uses FIPS 140-2 validated cryptographic modules inherited from AWS and Microsoft Azure cloud providers. Both AWS KMS and Azure Key Vault provide FIPS 140-2 validated encryption for OpenGov's data at rest and in transit.

Network Protection

An industry-leading Intrusion Detection Service (IDS) provides continuous monitoring across vulnerability detection, file integrity monitoring, configuration auditing, and threat correlation.

AWS Virtual Private Cloud (VPC) technology isolates compute instances and resources. Security Groups provide virtual firewall controls for traffic management. DDoS protection leverages AWS Shield, and pre-production assets are accessible only via VPN.

Host Protection & Access Control

Remote access to production systems is strictly limited to Engineering personnel on a time-bound, approved-business-case basis. Perpetual administrative access is prohibited. All access is fully audited, and multi-factor authentication (MFA) is required. AWS IAM provides fine-grained access control.

Application Protection

Application services run in isolated namespaces and containers with strict resource limits, preventing cross-service impact. Minimum replica counts ensure high availability.

Continuous Integration pipelines and vulnerability analysis services scan applications automatically at every lifecycle stage. Code repositories are continuously scanned for known defects, and compiled artifacts are re-scanned before distribution. An independent third-party penetration test is conducted at least annually.

Monitoring & Alerting

A comprehensive suite of industry-standard services covers availability, performance, security, logging, and metrics. OpenGov partners with a reputable managed security service provider for enhanced threat detection and incident response, with operational teams on standby 24/7.

Authentication & Authorization

OpenGov provides centralized identity and authentication support across its cloud platform. For governments that wish to leverage their own Enterprise Identity Provider (IdP), OpenGov supports integration with any SAML 2.0 compliant IdP, including both IdP-initiated and SP-initiated authentication flows.

Service Maintenance & Upgrades

Platform updates are performed without causing downtime, generally every two weeks during off-business hours. Feature flags enable controlled rollout, and services are deployed and rolled back individually to isolate potential issues.

Releases are executed through automated pipelines under the supervision of trained release managers who enforce change management discipline. Customers can subscribe to maintenance and incident notifications through the Help Center.

Open Source Libraries

OpenGov uses open-source software (OSS) libraries, packages, and frameworks as part of our products and services. OSS components are reviewed to ensure license compliance and to verify no adverse impact on OpenGov intellectual property. Copyright notices for specific packages are available upon request to moc.vognepo@lagel.

Organizational Security

OpenGov's Global Security Team is responsible for the strategy, compliance, and operational monitoring of our environment, partnering with an industry-leading managed security service provider for 24/7 detection and monitoring.

Our security strategy is grounded in the NIST Cybersecurity Framework. Policies and procedures are based on NIST 800-53 controls and audited annually for SOC 2 compliance. All personnel complete comprehensive security and data privacy training upon joining and at least annually. A robust phishing assessment program keeps team members aware of prevailing threats.

Accreditation

OpenGov is an accredited technology partner in the AWS Government Competency Program, recognized for technical proficiency and proven customer success in delivering mission-critical workloads. OpenGov undergoes an in-depth capability review by AWS every 12 months covering solution architecture and security.

Responsible Disclosure Policy

OpenGov values the security research community and welcomes collaboration to make our products and services more secure.

OpenGov believes that the disclosure of vulnerabilities is essential to improving the quality of our products and services. OpenGov values the insights of the security research community and welcomes disclosure and collaboration.

Through our responsible disclosure process OpenGov will work with security researchers and other vulnerability investigators to make our products and services more secure by providing a mechanism to privately report vulnerabilities with legitimacy and integrity. Responsible disclosure ensures that security infrastructure is tested and proven reliable. This process allows us to work collaboratively with the researchers to identify and mitigate vulnerabilities quickly in an ever-changing security environment.

Our Commitment to Researchers

We are committed to working collaboratively with security researchers and will respond to all valid submissions within the following timelines:

Milestone Target
Acknowledgment of receipt Within 3 business days
Initial triage and severity assessment Within 10 business days
Status updates on open findings Every 30 days until resolved
Critical/High severity remediation target 30 days from triage
Medium severity remediation target 90 days from triage
Low / Informational remediation target Best effort

Timelines may vary based on issue complexity. We will communicate any delays proactively.

In-Scope Systems

The following systems and assets are within scope for vulnerability disclosure:

  • OpenGov web applications accessible at *.opengov.com
  • OpenGov customer-facing APIs
  • OpenGov mobile applications (iOS and Android), where applicable
  • Authentication and identity flows, including SSO and SAML integrations

Out of Scope

The following are explicitly out of scope and should not be tested:

  • Third-party services and infrastructure not operated by OpenGov (including AWS, Azure, Cloudflare, and identity providers)
  • OpenGov corporate infrastructure (email, VPN, internal tooling)
  • HTML injection without demonstrated impact
  • Rate limiting and brute-force issues without demonstrated impact
  • Missing HTTP security headers (without demonstrated exploit chain)
  • Denial of Service (DoS/DDoS)
  • Social engineering of OpenGov employees

Reporting

To report a vulnerability, please send an email to moc.vognepo@ytiruces with the following information:

  • Contact Information
  • Vulnerability Type (e.g., SQLi, XSS)
  • Target/Scope (URL, IP, or App version)
  • Impact (What an attacker can do)
  • Step-by-step instructions to reproduce
  • Proof of Concept (Screenshots, video, or code)
  • HTTP Request/Response details
  • Environment details (Browser, OS)

Disclosure

OpenGov will follow standard industry practices for coordinated and responsible vulnerability disclosure. We ask all vulnerability reporters to do the same by allowing OpenGov the opportunity to verify and remediate reported vulnerabilities and for us to notify our affected customers and users before you disclose or share the vulnerability or methods to exploit with any third party.

OpenGov product security advisories will be made publicly available at https://trust.opengov.com.

 

Safe Harbor

OpenGov believes that ethical security research performed in good-faith provides an invaluable public service and has therefore provided this safe harbor program to encourage lawful, authorized security testing of our products and services. Accordingly, OpenGov will not initiate, pursue or recommend any law enforcement or civil lawsuits related to the specific actions taken by you to discover a security vulnerability, provided that such actions were undertaken consistent with this policy and in good faith, for the sole purpose of improving the overall security of our products and services, and not for any nefarious or otherwise unlawful purpose. OpenGov will not pursue civil action or refer researchers to law enforcement for security research conducted in good faith and in compliance with this policy.

You are, however, otherwise expected to comply with all applicable laws. If we become aware that government authorities have initiated legal action against you for security research conducted in strict accordance with the terms of this policy, we will advise the applicable government authorities that we consider your actions to have been "authorized" hereunder.

Please note that this safe-harbor policy will not apply to security activities performed in accordance with an executed, written agreement between you and OpenGov, and the terms of any such agreement shall prevail in their entirety over the terms of this policy, which shall not apply in such cases.

Expectations

  • Make a good-faith effort to avoid harm to OpenGov, our customers, and our end-users, including, but not limited to: privacy violations, destruction of data, and interruption or degradation of our services.
  • Do not access or attempt to access OpenGov offices, user offices, or user accounts.
  • Do not test for spam, perform phishing, social engineer, or intentionally cause denial of service issues for OpenGov services.
  • Do not access or attempt to access our customer or end-users' offices, data centers, user accounts, or attempt other forms of penetration testing without the direct, written approval of the system or property owner.
  • Comply with all applicable laws and regulations; do not disrupt or compromise any data that is not your own, or further exploit a confirmed vulnerability.
  • If a vulnerability provides unintended access to data, limit the amount of data you access to the minimum required to demonstrate a proof of concept.
  • After OpenGov validates your report, properly dispose of all copies of the data. Promptly report your findings to us through our approved channels.

If at any time you have concerns or are uncertain whether your security research is consistent with this policy, please inquire via moc.vognepo@ytiruces before going any further.

Security Advisories

OpenGov publishes advisories about identified and remediated security vulnerabilities through our Trust Center — the authoritative source for live security updates.

OpenGov publishes advisories for security vulnerabilities that affect our platform and are relevant to our customers. Advisories include details on the affected component, severity rating, and remediation status.

Live advisories are maintained at our Trust Center: trust.opengov.com

Advisories are issued when:

  • A vulnerability is confirmed and remediated in OpenGov-managed systems
  • A third-party component we rely on has a high/critical CVE with confirmed customer impact
  • A coordinated disclosure timeline is reached following responsible disclosure

To receive advisory notifications, subscribe via the OpenGov Trust Center.

To report a vulnerability, see our Vulnerability Disclosure Policy.

 

View Live Security Advisories

Our Trust Center provides real-time security advisories, compliance documentation, and status updates for all OpenGov products and services.

Visit Trust Center

Stay Informed

To receive notifications about new security advisories, subscribe to updates at the Trust Center.

Report a Vulnerability

Found a potential security issue? Read our Responsible Disclosure Policy for reporting guidelines, safe harbor provisions, and what to expect.

Have security questions?

Contact our Security Team at moc.vognepo@ytiruces for additional information, to report vulnerabilities, or for any concerns related to the security of the OpenGov platform.

Contact Security Team