Security overview
The controls behind the product, named specifically enough for a security questionnaire. If your reviewer needs this on letterhead, or needs our completed questionnaire rather than this page, ask and we will send it.
Written for Information technology and information security
Encryption
- In transit
- Every connection is encrypted with TLS 1.2 or higher. Plain HTTP is redirected, never served.
- At rest
- Documents, drafts, and account records are encrypted at rest with AES-256.
- Key management
- Encryption keys are managed by the hosting platform's key service and rotated on its schedule; keys are never held in application code or configuration.
Tenant isolation
- One city, one tenant
- Every organization's content is scoped to its own tenant. A query carries the tenant with it, so material from one city cannot be returned to another.
- Individual accounts
- A staff member who subscribes personally gets their own tenant, separate from any city contract, and it can be folded into a city plan later without re-keying their work.
Access control
- Role and department scope
- Administrators assign department access by role. A Parks coordinator sees Parks helpers, not City Attorney material.
- Draft privacy
- Drafts are private to the person who wrote them unless shared. Administrators see usage totals per department, not the content of a colleague's draft.
- Single sign-on
- Single sign-on through your existing identity provider is on the roadmap and is not available today. Accounts are email and password with administrator-controlled provisioning.
- Audit log
- Administrator actions — access granted or revoked, retention changed, usage purchased — are recorded with the actor and a timestamp.
Hosting and subprocessors
- Where it runs
- The application and its data are hosted in the United States.
- Subprocessors
- A current list of subprocessors — hosting, database, payments, and the AI provider — is supplied with the security documentation, including what each one processes.
- Payments
- Card payments are handled by Stripe. Card numbers never reach our servers.
Availability and incident response
- Backups
- Data is backed up on the hosting platform's managed schedule with point-in-time recovery.
- Notification
- If an incident affects your data we notify your administrator directly, within the window your contract specifies, with what we know and what we are doing.
- Reporting a concern
- Send anything that looks like a vulnerability to security@municiprompt.com. We would rather hear it from you than not hear it.
Your city's data is encrypted, isolated, and never used to train AI
Everything you upload or generate is encrypted in transit with TLS 1.2 or higher and encrypted at rest with AES-256. Each city's content is isolated to its own tenant, so no other organization can read it. Your documents and drafts are never used as training data by us or by our AI providers, and retention periods are set by your administrator.
The rest of the trust centre
Need this as a document?
Everything on this page is available as completed security documentation on letterhead, alongside contract terms and a pricing schedule your reviewer can attach to a solicitation.
