Security practices
Public-sector software has to be trustworthy below the surface, not just at the interface. This page covers how we handle data, where things run, and how to reach us about a security concern.
How we handle data
Data moves over TLS and rests encrypted. We collect the minimum the work requires, we never sell it, and it goes only to the providers that process it on our behalf. Access follows least privilege: the people who need it, and no one else. What this site itself collects is covered in our privacy policy.
Where things run
Our products run on SOC 2-audited cloud platforms for hosting, databases, and email delivery. We choose managed infrastructure deliberately: agencies get the security posture of major providers without new servers to maintain.
The accounts we operate
- Multi-factor authentication on the systems and services we administer.
- Unique credentials per service, no shared passwords.
- Secrets and keys live in managed environment configuration, never in code.
- Audit logs kept where the platform provides them.
On the products we deliver
Security ships with the work: HTTPS everywhere, role-based access where a product needs sign-in, and dependency updates as part of maintenance. We answer agency security reviews and vendor questionnaires as part of any engagement.
If something goes wrong
If we learn of an incident that affects a client's data, we notify that client promptly and plainly: what happened, what it touched, and what we are doing about it.
Questions about security
Email security@avenuecivic.com. IT and procurement teams reviewing us for an engagement can use the same address for questionnaires and documentation requests; we respond within one business day. Good-faith reports from security researchers reach us there too, and we act on them promptly.