Trust centre

Security overview

The controls behind the product, named specifically enough for a security questionnaire. If your reviewer needs this on letterhead, or needs our completed questionnaire rather than this page, ask and we will send it.

Written for Information technology and information security

Encryption

In transit
Every connection is encrypted with TLS 1.2 or higher. Plain HTTP is redirected, never served.
At rest
Documents, drafts, and account records are encrypted at rest with AES-256.
Key management
Encryption keys are managed by the hosting platform's key service and rotated on its schedule; keys are never held in application code or configuration.

Tenant isolation

One city, one tenant
Every organization's content is scoped to its own tenant. A query carries the tenant with it, so material from one city cannot be returned to another.
Individual accounts
A staff member who subscribes personally gets their own tenant, separate from any city contract, and it can be folded into a city plan later without re-keying their work.

Access control

Role and department scope
Administrators assign department access by role. A Parks coordinator sees Parks helpers, not City Attorney material.
Draft privacy
Drafts are private to the person who wrote them unless shared. Administrators see usage totals per department, not the content of a colleague's draft.
Single sign-on
Single sign-on through your existing identity provider is on the roadmap and is not available today. Accounts are email and password with administrator-controlled provisioning.
Audit log
Administrator actions — access granted or revoked, retention changed, usage purchased — are recorded with the actor and a timestamp.

Hosting and subprocessors

Where it runs
The application and its data are hosted in the United States.
Subprocessors
A current list of subprocessors — hosting, database, payments, and the AI provider — is supplied with the security documentation, including what each one processes.
Payments
Card payments are handled by Stripe. Card numbers never reach our servers.

Availability and incident response

Backups
Data is backed up on the hosting platform's managed schedule with point-in-time recovery.
Notification
If an incident affects your data we notify your administrator directly, within the window your contract specifies, with what we know and what we are doing.
Reporting a concern
Send anything that looks like a vulnerability to security@municiprompt.com. We would rather hear it from you than not hear it.

Your city's data is encrypted, isolated, and never used to train AI

Everything you upload or generate is encrypted in transit with TLS 1.2 or higher and encrypted at rest with AES-256. Each city's content is isolated to its own tenant, so no other organization can read it. Your documents and drafts are never used as training data by us or by our AI providers, and retention periods are set by your administrator.

The rest of the trust centre

Need this as a document?

Everything on this page is available as completed security documentation on letterhead, alongside contract terms and a pricing schedule your reviewer can attach to a solicitation.