Skip to content

Security and trust

53 of 53. No failures. No waivers. No deferrals.

In 2026, a state environmental agency independently reviewed PermitPro against every security and privacy requirement governing expanded platform use. The review was requirement by requirement. The result was unambiguous.

PermitPro met or exceeded all 53 requirements across all 9 domains.

This is not a self-assessment. It is an independent review conducted by a state agency's security and technology leadership, and it is available to any agency evaluating PermitPro.

Requirements met53 of 53Independent state agency review, 2026
Domains reviewed9Access control through change management

Security domains

Requirement by requirement

DomainRequirements reviewedResult
User accounts and access control17All met
System security and vulnerability management8All met
Data access and third-party disclosure6All met
Breach and unauthorized disclosure notification6All met
Exit strategy and data destruction9All met
Data ownership2All met
Record keeping and audit2All met
Requests for information and subpoenas1All met
Change management plan2All met
Total5353 of 53

Key security commitments

Specifics, not "enterprise-grade"

CommitmentDetail
U.S.-only infrastructureAWS us-east-1 / us-east-2 exclusively. No data outside U.S. borders. Ever.
AES-256 encryptionIn transit and at rest. TLS 1.2+ everywhere. HTTPS only.
Enterprise certificationsSOC 1/2/3, ISO 27001, FedRAMP (AWS infrastructure)
Your data is yoursFull ownership. No use for model training. Least-privilege access.
Breach notificationWritten notification within 24 hours. Full report within 3 business days.
Data destructionNIST SP 800-88 compliant. Certified within 30 days of contract end.
Audit log retention12 months minimum, exceeding the standard 6-month requirement.
Data portabilityComplete data export within 30 days of contract end. At no additional cost.
Outage notification15-day advance notice for planned outages. 60-minute notification for unplanned.

SSO and identity

Your staff logs in with what they already have

PermitPro supports SAML 2.0 / ADFS federation, meaning your staff authenticates through your existing identity provider. No new credentials. No new portals. No password management burden.

Role-based access controls are configured to your organizational structure during Phase 4. Access is provisioned and de-provisioned through your existing identity and access management processes.


AI governance

OMB M-25-21 compliant

PermitPro's governance framework meets the requirements of Office of Management and Budget (OMB) Memorandum M-25-21, which establishes standards for federal and federally-aligned AI use. This was independently confirmed as part of the CEQ Permitting Innovator selection process.

  • Human oversight required at every decision point. PermitPro never makes a final regulatory determination.

  • All outputs are logged, versioned, and auditable.

  • Model behavior is explainable and reviewable by your technical staff.

  • No autonomous action. Every output requires staff review and approval before use.

Ready to see PermitPro perform against your permit types?

A 30-minute scoping call is all it takes to confirm fit, permit types, and jurisdiction.