Security & data ownership

Built to be trusted with your city's records.

Deny-by-default access on every surface. Per-city isolation at the database layer. Signed records you can verify yourself. Your data leaves with you, always.

Written for city IT directors and procurement teams — how the platform is actually built, no marketing gloss. If your city has a security questionnaire, send it over and we'll complete it.

108 modules

Each covered by its own access test, run before every release

PCI DSS L1

Card fields are hosted by the payment processor — card numbers never touch our servers

100% yours

Full export on demand, open formats, no export fees

Nightly sealed

Civic receipts signed and sealed, independently verifiable

Data ownership

Your city owns its data — structurally, not contractually.

Ownership that depends on a clause in a contract isn't ownership. Every record your city creates is exportable, in open formats, through the same API our own applications use.

  • Full export on demand

    Every record belongs to your city, in open formats. Your records always leave with you.

  • API-first, headless

    The same open API our applications use is available to your city — nothing is trapped behind a proprietary interface.

  • No lock-in by design

    No per-record export fees. No "conversion project" to get your own records back.

  • Managed or self-hosted

    Choose our hosting at cost, or run the platform yourself. It's your city's platform either way.

Tenant isolation

One city, one isolated tenant.

Isolation enforced where it can't be bypassed — the database layer, not just application code.

Isolated by schema

  • Each city runs in its own isolated database schema.
  • Cross-tenant reads are blocked at the database layer, not only in code.
  • A bug in one city's module cannot reach another city's records.

Repeatable provisioning

  • Provisioning, migrations and upgrades are automated and repeatable.
  • The same audited process for every city — no bespoke one-off setups.
  • Verified by tests before every release.
Fail-closed access

Deny by default — on every surface.

Most platforms add permission checks where someone remembered to. Civic Kernel inverts that: nothing is reachable unless a valid, current entitlement explicitly enables it. A missing, expired or malformed permission enables nothing.

Try it — set an entitlement

Permits moduleentitlement · city of Greenville
All surfaces denied. No entitlement record — so nothing is enabled anywhere.
API endpoints
Denied
Public pages
Denied
Staff pages
Denied
Navigation
Denied
Search results
Denied
Reports
Denied
Exports
Denied
AI grounding
Denied
Background jobs
Denied

This contract is enforced by an automated test suite covering each of the platform's 108 modules individually — and it runs before every release.

Role- and scope-based staff access

  • A clerk who can process refunds cannot open treasury reconciliation.
  • A read-only role cannot fetch what it cannot see.

Turning a module off is reversible

  • Disabling a module removes all of its surfaces — without deleting records.
  • Re-enabling restores full function with data intact.
Payments

Card data never touches our servers.

Card numbers are entered on the payment processor's own hosted fields and never transit or rest on Civic Kernel infrastructure. Everything on our side reconciles against a ledger, not a guess.

Payment processor · hosted card fields

Where the card is entered

A certified provider hosts the payment fields. The resident's card details go straight to the certified processor.

  • Processor-hosted card surfaces
  • The processor carries the card-data obligations
  • Cities keep their own payment processor
Civic Kernel · ledger only

What we actually store

An obligation and its outcome — never a card number. Duplicate charges are structurally prevented.

  • Every charge tied to a durable, idempotent obligation before any provider call
  • Refunds reconcile against a ledger, not a guess
  • Capture is confirmed by a signed, tenant-scoped webhook — never by an optimistic redirect
Verifiable records

Verifiable records — not "trust us".

Selected official milestones mint signed civic receipts that are sealed nightly. Supported city documents can be checked independently against those receipts.

Signed & sealed

  • Selected official milestones mint signed civic receipts, sealed nightly.
  • Supported city documents can be independently verified — try the verification demo.
  • Administrative actions leave an audit trail: who, what, when.
WHO
Identified actor
Staff member and role recorded
WHAT
Exact action
Module enabled, role changed, permit issued
WHEN
Timestamped
Append-only, sealed nightly
Civic Receiptillustrative example · fictional record
ReferencePRM-4D5E6F70
ActionMechanical permit approved
Issued byM. Diaz · Reviewer
Timestamp2026-08-16 11:02:47 EDT
Signaturea3f9c1e7-08b24d65-9fe0c4a1-7d3b58ee-2c61f094

Sealed into the nightly cryptographic root — tamper-evident and independently checkable.

AI safety

AI that cannot leak what it cannot see.

The copilot is grounded in your city's live records, read-only, and drafts only — a person approves every action. It obeys the same fail-closed entitlements as everything else. And every AI feature is included free — never a paid add-on.

Grounded & read-only

It cites real records and cannot invent one. It drafts content for staff to approve — it never sends.

Cited to recordsRead-onlyHuman approves

Same fail-closed rules

If a module is off, the AI cannot ground on its data. Entitlements govern AI exactly as they govern staff.

Module off = invisibleScope-checked

Free AI, on your city’s own records

Every AI feature is included free — AI is never a paid add-on, and it is never metered per question, per seat or per city. It reads your city's own records, read-only, and drafts for a person to approve.

Included freeNot meteredRead-only
Infrastructure & operations

Boring where it counts, staged where it matters.

A bad release should be caught before your residents ever see it — so every release passes through the same gates.

Hosting & backups

  • US-based hosting, TLS on every connection.
  • DDoS protection and edge caching in front of the platform.
  • Nightly encrypted backups, off-site and independent of the primary host.
  • Managed hosting at cost — or self-host.

Every release, same gates

01
Test gates before merge
Including the 108-module access suite
02
Pre-deploy checks
Staged, never straight to production
03
Post-deploy sweep
Live pages and roles verified after ship
Accessibility & language access

Every resident, day one.

Accessibility and language access aren't a later phase — they ship with the platform.

  • Built to WCAG standards

    Tested across devices and viewports — not retrofitted after launch.

  • English & Spanish from day one

    Across the public site, notifications and every resident flow.

Security standards

Complete architectural transparency.

Built to modern security standards and best practices — and open about all of it. Your questionnaire answered in detail, with direct access to the engineers who built the platform.

Encryption in transitTLS on every connection
Least privilegeDeny-by-default everywhere
Tenant isolationPer-city, at the database layer
Test-gated releasesAudited and repeatable

Ask us the hard questions — that's what the demo is for.

A human engineer reads every message.

Questions, a security review, or a vulnerability to report — write to us directly. If your city has a questionnaire, send it and we'll complete it in detail.

[email protected] Request a demo Typically answered the same business day