Third Party Index

Snapshot 27324

Document
Security page
URL
https://opengov.com/security/
Fetched
HTTP status
200
Content type
text/html; charset=UTF-8
Fetch mode
static
Size
350505 bytes
SHA-256 (raw)
4de1c52c6d12777a2a5f69e10ea10ead0e93f8644b16960ad4d7721569b2b73a
SHA-256 (normalized text)
8385c6807acf5e181e817107d5a085be9b4ee1fe2c1e3b48888d152b822cdeb1

Normalized text

Scripts and page chrome removed; this is what change detection compares.

Security at OpenGov
The security and reliability of our platform — and the data entrusted to it — is our highest priority. Our program follows the NIST Cybersecurity Framework (CSF) and is regularly validated through independent audits and security assessments.
Explore Our Security Program
Dive into the areas that matter most for your security evaluation.
Infrastructure & Architecture
AWS hosting, encryption standards, network isolation, data protection, and high-availability design across our cloud platform.
Vulnerability Disclosure
Our responsible disclosure policy for security researchers, including reporting guidelines, safe harbor provisions, and expectations.
Security Advisories
Published advisories about identified and remediated vulnerabilities in OpenGov products and services.
Looking for compliance certifications, privacy documentation, or data processing agreements? Visit the OpenGov Trust Center
SOC 2 Type II
Security, Availability, Processing Integrity & Confidentiality
AES-256
Encryption at Rest
TLS 1.2+
Encryption in Transit
NIST
CSF 2.0 Framework · 800-53 Rev. 5 Policies & Controls
Infrastructure & Architecture
OpenGov’s cloud platform is built on AWS with defense-in-depth security across every layer — from physical data centers to application containers.
Physical & Environmental
he OpenGov Cloud platform is provisioned in the US East (Northern Virginia) Region of AWS, utilizing multiple Availability Zones interconnected with low-latency, highly-redundant networking. Pre-production environments are geo-isolated in the US West (Oregon) Region.
OpenGov personnel do not have physical access to data centers. Physical and environmental controls are inherited from AWS’s FedRAMP-authorized infrastructure. OpenGov’s application layer operates under its own SOC 2 Type II program.
Data Protection
Customer data is protected by TLS 1.2+ in transit. Cloudflare serves as the web application firewall, providing an additional defense layer against threats.
Databases use a multi-AZ deployment strategy for enhanced availability and durability. Regular backups and snapshots are stored across regional data centers. Real-time replication across AWS availability zones limits potential data loss to under one minute in a failover scenario.
Recovery Objectives
OpenGov maintains documented RTO/RPO objectives for all production systems. Our infrastructure meets a 4-hour RPO through real-time, multi-AZ database replication and 24-hour RTO via automated failover across Availability Zones. Recovery objectives are validated through regular backup and restoration testing, with results reviewed by security and reported to leadership.
Backup and Restoration Testing
OpenGov performs regular backup integrity and restoration testing to validate recoverability. Automated backups run continuously; restoration tests confirm data integrity and RTO/RPO targets. Results are documented and reviewed during annual SOC 2 audits.
FIPS 140-2 Validated Cryptography
OpenGov uses FIPS 140-2 validated cryptographic modules inherited from AWS and Microsoft Azure cloud providers. Both AWS KMS and Azure Key Vault provide FIPS 140-2 validated encryption for OpenGov’s data at rest and in transit.
Network Protection
An industry-leading Intrusion Detection Service (IDS) provides continuous monitoring across vulnerability detection, file integrity monitoring, configuration auditing, and threat correlation.
AWS Virtual Private Cloud (VPC) technology isolates compute instances and resources. Security Groups provide virtual firewall controls for traffic management. DDoS protection leverages AWS Shield, and pre-production assets are accessible only via VPN.
Host Protection & Access Control
Remote access to production systems is strictly limited to Engineering personnel on a time-bound, approved-business-case basis. Perpetual administrative access is prohibited. All access is fully audited, and multi-factor authentication (MFA) is required. AWS IAM provides fine-grained access control.
Application Protection
Application services run in isolated namespaces and containers with strict resource limits, preventing cross-service impact. Minimum replica counts ensure high availability.
Continuous Integration pipelines and vulnerability analysis services scan applications automatically at every lifecycle stage. Code repositories are continuously scanned for known defects, and compiled artifacts are re-scanned before distribution. An independent third-party penetration test is conducted at least annually.
Monitoring & Alerting
A comprehensive suite of industry-standard services covers availability, performance, security, logging, and metrics. OpenGov partners with a reputable managed security service provider for enhanced threat detection and incident response, with operational teams on standby 24/7.
Authentication & Authorization
OpenGov provides centralized identity and authentication support across its cloud platform. For governments that wish to leverage their own Enterprise Identity Provider (IdP), OpenGov supports integration with any SAML 2.0 compliant IdP, including both IdP-initiated and SP-initiated authentication flows.
Service Maintenance & Upgrades
Platform updates are performed without causing downtime, generally every two weeks during off-business hours. Feature flags enable controlled rollout, and services are deployed and rolled back individually to isolate potential issues.
Releases are executed through automated pipelines under the supervision of trained release managers who enforce change management discipline. Customers can subscribe to maintenance and incident notifications through the Help Center.
Open Source Libraries
OpenGov uses open-source software (OSS) libraries, packages, and frameworks as part of our products and services. OSS components are reviewed to ensure license compliance and to verify no adverse impact on OpenGov intellectual property. Copyright notices for specific packages are available upon request to [email protected].
Organizational Security
OpenGov’s Global Security Team is responsible for the strategy, compliance, and operational monitoring of our environment, partnering with an industry-leading managed security service provider for 24/7 detection and monitoring.
Our security strategy is grounded in the NIST Cybersecurity Framework. Policies and procedures are based on NIST 800-53 controls and audited annually for SOC 2 compliance. All personnel complete comprehensive security and data privacy training upon joining and at least annually. A robust phishing assessment program keeps team members aware of prevailing threats.
Accreditation
OpenGov is an accredited technology partner in the AWS Government Competency Program, recognized for technical proficiency and proven customer success in delivering mission-critical workloads. OpenGov undergoes an in-depth capability review by AWS every 12 months covering solution architecture and security.
Responsible Disclosure Policy
OpenGov values the security research community and welcomes collaboration to make our products and services more secure.
OpenGov believes that the disclosure of vulnerabilities is essential to improving the quality of our products and services. OpenGov values the insights of the security research community and welcomes disclosure and collaboration.
Through our responsible disclosure process OpenGov will work with security researchers and other vulnerability investigators to make our products and services more secure by providing a mechanism to privately report vulnerabilities with legitimacy and integrity. Responsible disclosure ensures that security infrastructure is tested and proven reliable. This process allows us to work collaboratively with the researchers to identify and mitigate vulnerabilities quickly in an ever-changing security environment.
Our Commitment to Researchers
We are committed to working collaboratively with security researchers and will respond to all valid submissions within the following timelines:
Milestone	Target
Acknowledgment of receipt	Within 3 business days
Initial triage and severity assessment	Within 10 business days
Status updates on open findings	Every 30 days until resolved
Critical/High severity remediation target	30 days from triage
Medium severity remediation target	90 days from triage
Low / Informational remediation target	Best effort
Timelines may vary based on issue complexity. We will communicate any delays proactively.
In-Scope Systems
The following systems and assets are within scope for vulnerability disclosure:
OpenGov web applications accessible at *.opengov.com
OpenGov customer-facing APIs
OpenGov mobile applications (iOS and Android), where applicable
Authentication and identity flows, including SSO and SAML integrations
Out of Scope
The following are explicitly out of scope and should not be tested:
Third-party services and infrastructure not operated by OpenGov (including AWS, Azure, Cloudflare, and identity providers)
OpenGov corporate infrastructure (email, VPN, internal tooling)
HTML injection without demonstrated impact
Rate limiting and brute-force issues without demonstrated impact
Missing HTTP security headers (without demonstrated exploit chain)
Denial of Service (DoS/DDoS)
Social engineering of OpenGov employees
Reporting
To report a vulnerability, please send an email to [email protected] with the following information:
Contact Information
Vulnerability Type (e.g., SQLi, XSS)
Target/Scope (URL, IP, or App version)
Impact (What an attacker can do)
Step-by-step instructions to reproduce
Proof of Concept (Screenshots, video, or code)
HTTP Request/Response details
Environment details (Browser, OS)
Disclosure
OpenGov will follow standard industry practices for coordinated and responsible vulnerability disclosure. We ask all vulnerability reporters to do the same by allowing OpenGov the opportunity to verify and remediate reported vulnerabilities and for us to notify our affected customers and users before you disclose or share the vulnerability or methods to exploit with any third party.
OpenGov product security advisories will be made publicly available at https://trust.opengov.com.
Safe Harbor
OpenGov believes that ethical security research performed in good-faith provides an invaluable public service and has therefore provided this safe harbor program to encourage lawful, authorized security testing of our products and services. Accordingly, OpenGov will not initiate, pursue or recommend any law enforcement or civil lawsuits related to the specific actions taken by you to discover a security vulnerability, provided that such actions were undertaken consistent with this policy and in good faith, for the sole purpose of improving the overall security of our products and services, and not for any nefarious or otherwise unlawful purpose. OpenGov will not pursue civil action or refer researchers to law enforcement for security research conducted in good faith and in compliance with this policy.
You are, however, otherwise expected to comply with all applicable laws. If we become aware that government authorities have initiated legal action against you for security research conducted in strict accordance with the terms of this policy, we will advise the applicable government authorities that we consider your actions to have been “authorized” hereunder.
Please note that this safe-harbor policy will not apply to security activities performed in accordance with an executed, written agreement between you and OpenGov, and the terms of any such agreement shall prevail in their entirety over the terms of this policy, which shall not apply in such cases.
Expectations
Make a good-faith effort to avoid harm to OpenGov, our customers, and our end-users, including, but not limited to: privacy violations, destruction of data, and interruption or degradation of our services.
Do not access or attempt to access OpenGov offices, user offices, or user accounts.
Do not test for spam, perform phishing, social engineer, or intentionally cause denial of service issues for OpenGov services.
Do not access or attempt to access our customer or end-users’ offices, data centers, user accounts, or attempt other forms of penetration testing without the direct, written approval of the system or property owner.
Comply with all applicable laws and regulations; do not disrupt or compromise any data that is not your own, or further exploit a confirmed vulnerability.
If a vulnerability provides unintended access to data, limit the amount of data you access to the minimum required to demonstrate a proof of concept.
After OpenGov validates your report, properly dispose of all copies of the data. Promptly report your findings to us through our approved channels.
If at any time you have concerns or are uncertain whether your security research is consistent with this policy, please inquire via [email protected] before going any further.
Security Advisories
OpenGov publishes advisories about identified and remediated security vulnerabilities through our Trust Center — the authoritative source for live security updates.
OpenGov publishes advisories for security vulnerabilities that affect our platform and are relevant to our customers. Advisories include details on the affected component, severity rating, and remediation status.
Live advisories are maintained at our Trust Center: trust.opengov.com
Advisories are issued when:
A vulnerability is confirmed and remediated in OpenGov-managed systems
A third-party component we rely on has a high/critical CVE with confirmed customer impact
A coordinated disclosure timeline is reached following responsible disclosure
To receive advisory notifications, subscribe via the OpenGov Trust Center.
To report a vulnerability, see our Vulnerability Disclosure Policy.
View Live Security Advisories
Our Trust Center provides real-time security advisories, compliance documentation, and status updates for all OpenGov products and services.
Visit Trust Center
Stay Informed
To receive notifications about new security advisories, subscribe to updates at the Trust Center.
Report a Vulnerability
Found a potential security issue? Read our Responsible Disclosure Policy for reporting guidelines, safe harbor provisions, and what to expect.
Have security questions?
Contact our Security Team at [email protected] for additional information, to report vulnerabilities, or for any concerns related to the security of the OpenGov platform.
Contact Security Team