Security and trust
53 of 53. No failures. No waivers. No deferrals.
In 2026, a state environmental agency independently reviewed PermitPro against every security and privacy requirement governing expanded platform use. The review was requirement by requirement. The result was unambiguous.
PermitPro met or exceeded all 53 requirements across all 9 domains.
This is not a self-assessment. It is an independent review conducted by a state agency's security and technology leadership, and it is available to any agency evaluating PermitPro.
Security domains
Requirement by requirement
| Domain | Requirements reviewed | Result |
|---|---|---|
| User accounts and access control | 17 | All met |
| System security and vulnerability management | 8 | All met |
| Data access and third-party disclosure | 6 | All met |
| Breach and unauthorized disclosure notification | 6 | All met |
| Exit strategy and data destruction | 9 | All met |
| Data ownership | 2 | All met |
| Record keeping and audit | 2 | All met |
| Requests for information and subpoenas | 1 | All met |
| Change management plan | 2 | All met |
| Total | 53 | 53 of 53 |
Key security commitments
Specifics, not "enterprise-grade"
| Commitment | Detail |
|---|---|
| U.S.-only infrastructure | AWS us-east-1 / us-east-2 exclusively. No data outside U.S. borders. Ever. |
| AES-256 encryption | In transit and at rest. TLS 1.2+ everywhere. HTTPS only. |
| Enterprise certifications | SOC 1/2/3, ISO 27001, FedRAMP (AWS infrastructure) |
| Your data is yours | Full ownership. No use for model training. Least-privilege access. |
| Breach notification | Written notification within 24 hours. Full report within 3 business days. |
| Data destruction | NIST SP 800-88 compliant. Certified within 30 days of contract end. |
| Audit log retention | 12 months minimum, exceeding the standard 6-month requirement. |
| Data portability | Complete data export within 30 days of contract end. At no additional cost. |
| Outage notification | 15-day advance notice for planned outages. 60-minute notification for unplanned. |
SSO and identity
Your staff logs in with what they already have
PermitPro supports SAML 2.0 / ADFS federation, meaning your staff authenticates through your existing identity provider. No new credentials. No new portals. No password management burden.
Role-based access controls are configured to your organizational structure during Phase 4. Access is provisioned and de-provisioned through your existing identity and access management processes.
AI governance
OMB M-25-21 compliant
PermitPro's governance framework meets the requirements of Office of Management and Budget (OMB) Memorandum M-25-21, which establishes standards for federal and federally-aligned AI use. This was independently confirmed as part of the CEQ Permitting Innovator selection process.
Human oversight required at every decision point. PermitPro never makes a final regulatory determination.
All outputs are logged, versioned, and auditable.
Model behavior is explainable and reviewable by your technical staff.
No autonomous action. Every output requires staff review and approval before use.