generated: '2026-08-04' method: searched probe: true source: https://trust.opengov.com/ url: https://trust.opengov.com/ secondary_url: https://opengov.com/security/ certifications: - SOC 2 Type 2 - SOC 3 - TX-RAMP - AZ RAMP - GovRAMP - GDPR - CCPA - CPRA - VPAT frameworks: - NIST CSF 2.0 - NIST 800-53 Rev. 5 reports: - name: SOC 2 Report access: available for download from the trust center - name: SOC 3 Report access: available for download from the trust center - name: Penetration Test Report access: available for download from the trust center - name: Application Penetration Testing documentation access: available for download from the trust center controls: - Security Operations Center (SOC) - Incident response program with designated response personnel - Annual third-party penetration test and risk assessment - Managed security service provider for threat detection and incident response - Employee privacy training - Phishing training - Security awareness training - Business Continuity Plan (BCP) - Disaster Recovery Plan (DRP) cryptography: - AES-256 at rest - TLS 1.2+ in transit - FIPS 140-2 validated cryptography infrastructure: provider: Amazon Web Services accreditation: AWS Government Competency Program; strategic AWS partnership contacts: general: trust@opengov.com security: security@opengov.com grc: grc@opengov.com caveat: >- The trust center itself states "Our policies are currently under review and revision" and "We are working on our security compliance. We can provide completed questionnaires upon request." Recorded verbatim rather than smoothed over — several policy documents are on request rather than posted. evidence: - source: https://trust.opengov.com/ http_status: 200 fetched: '2026-08-04' keywords: - soc 2 - soc 3 - tx-ramp - govramp - gdpr - trust center - pentest report - source: https://opengov.com/security/ http_status: 200 fetched: '2026-08-04' keywords: - soc 2 type ii - nist csf 2.0 - nist 800-53 - fips 140-2 - responsible disclosure