The security standards Spotbookr works to, and how they shape the way we build and run systems.
Standards
Our security program follows the frameworks published by the U.S. National Institute of Standards and Technology (NIST), the reference used across federal, state and local government.
Our security program is organized around the six functions of the NIST Cybersecurity Framework 2.0: Govern, Identify, Protect, Detect, Respond and Recover.
NIST Special Publication 800-171 sets the requirements for protecting controlled unclassified information in non-federal systems and organizations.
Our policies, controls and procedures follow the structure and practices set out in the NIST framework.
In Practice
The same controls apply to every product we run and every system we build for a client.
People see and change only what their role allows. Access can be scoped by team, municipality or department.
Data is encrypted in transit and at rest.
A time-stamped record of who created, changed, approved or exported a record.
Support for SSO and SAML, so access follows your own identity provider and its policies.
Consumer signals are anonymized and aggregated, and personal data is not sold.
Clients keep ownership of their records and can export them in common formats.
See the partner programs we belong to and the industries and codes we work under.