Security & trust

Built for data that can't leak.

HCV programs handle some of the most sensitive personal data in local government. We treat protecting it — and being able to prove you protected it — as a core feature, not an afterthought.

How we protect it

Three pillars of trust.

Encrypted, end to end
Data is encrypted in transit (TLS 1.2+) and at rest (AES-256). Keys are managed and rotated; secrets never live in the application layer.
Least-privilege access
Role-based access control scopes every user to exactly what their job requires. SSO and SAML keep identity in your control, not ours.
Immutable audit trail
Every record change is logged with who, what, and when. The same trail that satisfies a HUD review also tells you exactly what happened, always.
Compliance posture

Aligned with what your program is held to.

Honest about where we are: shipped where it says shipped, in progress where it says in progress.

SOC 2 Type II
In progress
HUD-aligned
50058 · SEMAP
WCAG 2.1 AA
Accessibility
Data residency
US-based

SOC 2 Type II audit is underway. We're happy to share our current posture and roadmap under NDA.

The details

Practices we hold to.

Encryption everywhere
TLS 1.2+ in transit, AES-256 at rest, across every service.
SSO & MFA
SAML single sign-on with enforced multi-factor for staff accounts.
Role-based access
Granular permissions scoped to job function, reviewed regularly.
Continuous backups
Automated, encrypted backups with point-in-time recovery.
Audit logging
Immutable, queryable logs of every record-level change.
Vulnerability management
Routine scanning, patching, and independent penetration testing.
Least-data principle
We collect only what the program requires — nothing speculative.
Incident response
A documented plan with defined roles and notification timelines.

Need our security documentation?

We'll walk your IT and compliance teams through our posture, architecture, and roadmap.

Request documentation Tour the platform