Deny-by-default access on every surface. Per-city isolation at the database layer. Signed records you can verify yourself. Your data leaves with you, always.
Written for city IT directors and procurement teams — how the platform is actually built, no marketing gloss. If your city has a security questionnaire, send it over and we'll complete it.
Each covered by its own access test, run before every release
Card fields are hosted by the payment processor — card numbers never touch our servers
Full export on demand, open formats, no export fees
Civic receipts signed and sealed, independently verifiable
Ownership that depends on a clause in a contract isn't ownership. Every record your city creates is exportable, in open formats, through the same API our own applications use.
Every record belongs to your city, in open formats. Your records always leave with you.
The same open API our applications use is available to your city — nothing is trapped behind a proprietary interface.
No per-record export fees. No "conversion project" to get your own records back.
Choose our hosting at cost, or run the platform yourself. It's your city's platform either way.
Isolation enforced where it can't be bypassed — the database layer, not just application code.
Most platforms add permission checks where someone remembered to. Civic Kernel inverts that: nothing is reachable unless a valid, current entitlement explicitly enables it. A missing, expired or malformed permission enables nothing.
Try it — set an entitlement
This contract is enforced by an automated test suite covering each of the platform's 108 modules individually — and it runs before every release.
Card numbers are entered on the payment processor's own hosted fields and never transit or rest on Civic Kernel infrastructure. Everything on our side reconciles against a ledger, not a guess.
A certified provider hosts the payment fields. The resident's card details go straight to the certified processor.
An obligation and its outcome — never a card number. Duplicate charges are structurally prevented.
Selected official milestones mint signed civic receipts that are sealed nightly. Supported city documents can be checked independently against those receipts.
Sealed into the nightly cryptographic root — tamper-evident and independently checkable.
The copilot is grounded in your city's live records, read-only, and drafts only — a person approves every action. It obeys the same fail-closed entitlements as everything else. And every AI feature is included free — never a paid add-on.
It cites real records and cannot invent one. It drafts content for staff to approve — it never sends.
If a module is off, the AI cannot ground on its data. Entitlements govern AI exactly as they govern staff.
Every AI feature is included free — AI is never a paid add-on, and it is never metered per question, per seat or per city. It reads your city's own records, read-only, and drafts for a person to approve.
A bad release should be caught before your residents ever see it — so every release passes through the same gates.
Accessibility and language access aren't a later phase — they ship with the platform.
Tested across devices and viewports — not retrofitted after launch.
Across the public site, notifications and every resident flow.
Built to modern security standards and best practices — and open about all of it. Your questionnaire answered in detail, with direct access to the engineers who built the platform.
Ask us the hard questions — that's what the demo is for.
Questions, a security review, or a vulnerability to report — write to us directly. If your city has a questionnaire, send it and we'll complete it in detail.