CivAll is built with security at its core. We protect your data with enterprise-grade infrastructure, rigorous compliance standards, and continuous monitoring—so you can focus on serving your community.
Stay ahead of evolving regulatory expectations. Our platform undergoes regular independent verification of security, privacy, and compliance controls to meet the highest standards.
Independent attestation that our security controls are suitably designed to meet the AICPA trust services criteria for security, availability, and confidentiality.
Independent third-party audit attesting that our security controls operated effectively over time across security, availability, and confidentiality.
24/7 internal security monitoring combined with independent third-party penetration testing detects threats and finds vulnerabilities before anyone else does.
CivAll is built on 15 years of Social News Desk's experience serving cities, counties, states, and public institutions. We understand that government agencies prioritize the security of resident and government data above all else—and we've built our platform to meet those exacting standards.
The documents procurement, IT, and legal teams ask for—organized by category. Public documents open directly; audit reports are shared under NDA on request.
Audit reports and security documentation, shared under NDA on request.
SOC 2 Reports (Type I & Type II)
Independent audit reports on the design and operating effectiveness of our security controls against the AICPA trust services criteria.
Under NDA
Penetration Test Summary
Summary of the most recent independent penetration test of the platform.
Under NDA
Sub-Processor List
Third-party sub-processors with access to customer data, and what each one processes.
On request
AI Governance Policy
How artificial intelligence in the CivAll Platform is governed: principles, data handling, human oversight, and vendor commitments.
v1.1 · September 2026
AI Capability Disclosure
Per-capability description of AI in the CivAll Platform for customer inventories and vendor reviews, provided under agreement or NDA.
On request
How data is collected, used, protected, and processed.
Our accessibility policy, conformance reporting, and remediation plan.
Digital Accessibility Policy
Our commitment: standards targeted, how accessibility is built in, and how to report issues.
v1.0 · August 2026
Accessibility Conformance Report (VPAT 2.5 INT)
Formal conformance report for the CivAll Platform: WCAG 2.1, WCAG 2.2, and Revised Section 508.
v1.0 · May 2026
Accessibility Remediation Roadmap
Planned remediation for the known conformance gaps recorded in the ACR, tied to ACR update cycles.
v1.0 · August 2026
Agreements and policies governing the platform and services.
Browse all legal documents
Master Subscription Agreement, Service Level Agreement, Acceptable Use Policy, Data Processing Addendum, product schedules, and website terms—each with its effective date.
Go to Legal →
Powered by Social News Desk • Made in America
We implement comprehensive technical, physical, and organizational safeguards to protect sensitive government data from unauthorized access, misuse, or disclosure.
All data is encrypted in transit using TLS 1.3 and at rest using AES-256 encryption. Database backups and file storage are encrypted with customer-specific keys.
Role-based access control (RBAC) ensures users only access what they need. Multi-factor authentication is required for all administrative access.
Continuous security monitoring detects and alerts on suspicious activity. Our security team investigates anomalies and responds to incidents around the clock.
Weekly automated security scans identify vulnerabilities. Third-party penetration tests are conducted annually. Critical patches are applied within 24 hours.
All employees complete background checks and mandatory security awareness training. Access is granted on a least-privilege basis and revoked immediately upon departure.
Documented incident response procedures ensure rapid containment and recovery. Affected customers are notified within 72 hours of confirmed data breaches.
CivAll runs on enterprise-grade cloud infrastructure designed for government workloads, with multiple layers of redundancy and geographic distribution.
Guaranteed availability with service credits
Enterprise-grade facilities with physical security controls
Multi-region redundancy for disaster recovery
30-day retention with point-in-time recovery
Enterprise-grade traffic filtering and mitigation
We believe in data minimization and transparency. CivAll only collects and processes the data necessary to provide our services—nothing more.
Privacy, security, legal, and accessibility documentation is organized in the Trust Document Center. Public documents open directly; audit reports are shared under NDA.
Found a security vulnerability? We appreciate responsible disclosure and work with the security community to keep our platform safe.
Our team is happy to answer detailed security questions, provide documentation, and complete your security questionnaire.