Security & trust

Your jurisdiction's records, kept separate and safe.

Every jurisdiction's data is walled off from every other — kept apart in the database itself, not left to chance. Your staff sign in the way your government already does, every change is on the record when an auditor asks, and you can take your data with you whenever you choose. Here is exactly how that works, in plain terms.

Tenant isolation

One system, walled off for every jurisdiction.

Civic Mesa runs many jurisdictions on one platform, but no jurisdiction can ever reach another's records. The separation is enforced in the database itself, so it holds even if someone makes a mistake in the software above it.

One system — walled off per jurisdiction
Mesa Verde Countyits own cases, permits & residents
walled off — no crossing over
Ridgeline Countyits own cases, permits & residents
A request that can't prove which jurisdiction it belongs to gets nothing back — every time.
Separate by design

One jurisdiction can never see another's data. The separation is built into the database, so it holds even if there's a bug in the application code above it.

Closed unless it's allowed

Access is denied by default. There is no hidden setting or back door that quietly opens up another jurisdiction's records.

Sign in the way you already do

Use your existing Microsoft sign-in, so access follows the accounts your IT team already manages. Microsoft sign-in

How it holds up

The protections your IT and records team will ask about.

Every jurisdiction kept separate

Each jurisdiction's records are walled off from every other in the database itself — so one government's data never reaches another.

Closed by default

If the system can't confirm which jurisdiction a request belongs to, it returns nothing. Access stays closed unless it's clearly allowed.

Right people, right records

Staff get exactly the access their role needs, and nothing more. You set the permissions once, and the system enforces them everywhere.

Sign in with Microsoft

Use the Microsoft accounts your government already has, so access follows the people your IT team manages — nothing new to hand out or take back.

Every change tracked

Edits and status changes are recorded as they happen — who, what, and when — so you can answer a resident, attorney, or auditor straight from the system.

Runs on Microsoft Azure

Hosted on Microsoft's secure cloud, with nothing for your government to patch or maintain — and traffic encrypted in transit over HTTPS.

No lock-in

Your data stays portable.

Security shouldn't mean captivity. You can export your jurisdiction's records at any time in open formats, and the in-app Import Wizard brings your history over from a legacy vendor without a clean-room project.

  • Export any time. Pull your records in open formats whenever you want — no exit fee, no ransom on your own history.
  • Bring your history in. The Import Wizard maps your current vendor's exports, with a read-only dry run before anything is written.
  • See it and own it. Read-only transparency surfaces and CSV exports mean the numbers on screen match the numbers in the record.

Read our data-ownership commitment

Portable by design
Exportopen formats, any time
Importfrom your legacy vendor
Deleteon request, per your agreement
You are never held hostage to keep your own records.
An honest word on certifications

What's true today — not a promise for later.

Civic Mesa is not SOC 2 certified. We're building toward formal certification, and we won't claim a badge we haven't earned. Everything on this page describes how the system actually behaves right now — the tenant isolation, the Microsoft sign-in, the audit trail, and the data portability are live, not roadmap. We're glad to walk your IT and records team through exactly how each one works, in plain terms, before you commit.

Live today

Per-tenant isolation in the database, deny-by-default access, role-based permissions, Microsoft sign-in, a change audit trail, and HTTPS in transit.

On the roadmap

Formal third-party attestation. We're happy to share our current progress and security documentation under NDA with your team.

Ask us anything

Bring your security questionnaire. We'd rather answer plainly than hide behind a logo — email hello@civicmesa.com.

Talk to us

Bring us your security questionnaire.

Book a demo and we'll walk your IT and records team through tenant isolation, sign-in, auditing, and data export on your own jurisdiction's pilot — before any commitment.