OptimoGov North America

Trust Center

Everything your IT and legal reviewers will ask for, in one place.

This page states what OptimoGov holds, where your data lives, how the resident portal handles accessibility, and what we have not certified. The last part matters as much as the first. Ask every vendor you evaluate for the same disclosure.

Last reviewed September 2026. Security contact: security@optimogov.com

Certifications
ISO 27001, SOC 2 Type II, SOC 1 Type I, PCI DSS
Hosting
Microsoft Azure, US and Canadian regions
Availability
99.9% contracted, quarterly penetration testing
Accessibility
Resident portal built to WCAG 2.1 Level AA

Certifications and attestations

What we hold, and what we do not.

Several vendors in this category publish a security page that names no certification at all. Others hold a strong authorization and bury it in a blog post. Below is the full ledger, including the gaps.

Read this first

Platform versus infrastructure

Some vendors present Microsoft Azure's certifications as their own. We separate them. Where a control is inherited from Azure we say so, and where it is our own audited scope we say that instead.

OptimoGov accreditation marks: ISO 27001, SOC 2, SOC 1, PCI DSS, Cyber Essentials and Microsoft Partner
  • ISO 27001

    Certified

    Information security management system certification covering the OptimoGov platform and its operating organization. Certificate and scope statement supplied in the security pack.

  • SOC 2 Type II

    Report available

    Independent examination of security, availability and confidentiality controls over a defined observation period. Report released under NDA on request.

  • SOC 1 Type I

    Report available

    Controls relevant to financial reporting, which your auditor may request given the platform handles receipting and revenue.

  • PCI DSS

    Compliant

    Card data is handled by the gateway, not stored in OptimoGov. Attestation of compliance and the scope of our cardholder data environment are in the security pack.

  • Penetration testing

    Quarterly

    Independent testing four times a year against the platform and the resident portal, with remediation tracked to closure. Executive summary available on request.

  • Cyber Essentials

    Held, UK scheme

    A United Kingdom government scheme. We list it for completeness and note that it carries no recognition in United States or Canadian procurement.

  • GovRAMP, formerly StateRAMP

    Not held

    We are not currently on the GovRAMP authorized product list in any status. Where your state requires GovRAMP or a state equivalent such as TX-RAMP, tell us during the RFP and we will confirm our position on the required timeline rather than let you find out at contract.

  • FedRAMP

    Not held

    Not held and not on our roadmap. OptimoGov is sold to state, local and municipal government, not to federal agencies.

  • Cooperative purchasing contracts

    None currently

    We do not hold a Sourcewell, OMNIA Partners, NASPO ValuePoint, BuyBoard or TIPS contract at present. Where your policy allows it, we can support a piggyback off an existing award, a state term contract or a sole source justification. See procurement paths.

Data residency and privacy

Your data stays in your country.

Region is selected at contract and does not change without your written instruction. For Canadian agencies this is a legal requirement rather than a preference, and we treat it that way.

Hosting, retention and privacy posture
ItemUnited StatesCanada
Primary hostingMicrosoft Azure, US regionMicrosoft Azure, Canadian region
Backup locationAzure Backup Vault, same countryAzure Backup Vault, same country
EncryptionTLS in transit, encrypted at restTLS in transit, encrypted at rest
Applicable privacy regimesState privacy laws including CCPA and CPRA, COPPA for participants under 13, FERPA where school data is involvedPIPEDA, provincial privacy legislation, Quebec Law 25
Language of serviceEnglishEnglish, with French for Quebec deployments
Data processing agreementAvailable for signatureAvailable for signature
Subprocessor listPublished and versionedPublished and versioned
Data export on exitFull structured export in machine-readable formatFull structured export in machine-readable format

Quebec deployments: OptimoGov supports French-language resident-facing content and GST, HST and QST handling. Confirm the current scope of French coverage with us before issuing a solicitation that requires it.

Accessibility

The pages residents use are the pages that have to conform.

The Department of Justice rule under ADA Title II requires state and local government web content and mobile applications to meet WCAG 2.1 Level AA. A resident reservation and registration portal is in scope. So is the confirmation email, the invoice and the mobile view.

Compliance dateApril 26, 2027

Public entities serving a population of 50,000 or more.

Compliance dateApril 26, 2028

Public entities under 50,000, and every special district government regardless of size. Independent park and recreation districts fall here.

Dates reflect the compliance extension published in April 2026. The WCAG 2.1 AA standard itself did not change.

  • Accessibility conformance report. An ACR for the resident portal covering WCAG 2.1 Level AA, supplied to your ADA coordinator and suitable for your purchasing file.
  • Keyboard and screen reader operation. Every booking, registration and payment path completable without a mouse and tested with screen reader software.
  • Contrast and text sizing. AA contrast ratios throughout, resizable to 200% without loss of content or function, and no meaning carried by color alone.
  • Forms that announce their errors. Labels, instructions and validation messages exposed to assistive technology rather than shown only as red outlines.
  • Documents residents receive. Permits, invoices, receipts and confirmations generated as tagged, accessible PDFs.
  • A named accessibility contact and a remediation commitment. A route for a resident or your ADA coordinator to report a barrier, with stated response times.
  • Canada. AODA in Ontario and the Accessible Canada Act are addressed by the same WCAG 2.1 AA conformance work.

Platform security

Controls your IT reviewer will score.

Identity

Single sign-on and provisioning

Microsoft Entra ID, Azure AD, ADFS and SAML 2.0 for staff. Role-based permissions down to facility and function level. Resident accounts are separate from staff identity by design.

Availability

Uptime and recovery

99.9% availability contracted. Disaster recovery plan with defined recovery point and recovery time objectives, stated in your agreement rather than left general.

Auditability

Audit trail

Who changed a permit, a rate, a refund or a deposit deduction, when, and what the value was before. Retained and exportable, which is what a records request or an internal audit needs.

Payments

Card data handling

Card data is tokenized at the gateway. OptimoGov does not store primary account numbers. Reduces your PCI scope rather than extending it.

Assurance

Testing and monitoring

Quarterly independent penetration testing, secure development policy, dependency and vulnerability monitoring, and remediation tracked to closure.

Disclosure

Vulnerability reporting

A published route for researchers and for your own security team to report an issue, with acknowledgement and remediation commitments. Report a vulnerability

Documentation

Ask once, get the whole file.

One request returns everything your security questionnaire, your attorney and your purchasing officer need. Reports issued under NDA are marked below.

  • ISO 27001 certificate and scope statement
  • SOC 2 Type II report and SOC 1 Type I report, under NDA
  • PCI DSS attestation of compliance and cardholder data environment scope
  • Accessibility conformance report for the resident portal, WCAG 2.1 Level AA
  • Penetration test executive summary, most recent quarter
  • Data processing agreement and subprocessor list
  • Disaster recovery and business continuity plan summary with RPO and RTO
  • Completed security questionnaire, including HECVAT where your institution uses it
  • Insurance certificates, W-9 and financial references
  • Sample contract and service level terms

Send us your security questionnaire before the demo.

We would rather your IT reviewer clear us in week one than raise a blocker in week nine. Send the questionnaire and we will return it completed.