Spotbookr Logo

Certifications

The security standards Spotbookr works to, and how they shape the way we build and run systems.

NIST CSF 2.0 NIST SP 800-171 Encryption in transit and at rest Audit logging

Standards

Built to recognized security standards

Our security program follows the frameworks published by the U.S. National Institute of Standards and Technology (NIST), the reference used across federal, state and local government.

Cybersecurity Framework

Aligned with NIST CSF 2.0 Standards

Our security program is organized around the six functions of the NIST Cybersecurity Framework 2.0: Govern, Identify, Protect, Detect, Respond and Recover.

Controlled Unclassified Information

Self-Certified NIST SP 800-171

NIST Special Publication 800-171 sets the requirements for protecting controlled unclassified information in non-federal systems and organizations.

NIST Framework

NIST Framework Compliant

Our policies, controls and procedures follow the structure and practices set out in the NIST framework.

In Practice

What the standards look like in our systems

The same controls apply to every product we run and every system we build for a client.

Role-based access

People see and change only what their role allows. Access can be scoped by team, municipality or department.

Encryption

Data is encrypted in transit and at rest.

Audit history

A time-stamped record of who created, changed, approved or exported a record.

Single sign-on

Support for SSO and SAML, so access follows your own identity provider and its policies.

Privacy by design

Consumer signals are anonymized and aggregated, and personal data is not sold.

Data ownership

Clients keep ownership of their records and can export them in common formats.

Working on a solicitation?

See the partner programs we belong to and the industries and codes we work under.