Security & Trust
EffiGov handles calls between residents and their local government. This page is the plain-language overview of how we protect that information: US-based data infrastructure, encryption, least-privilege access, and independently verifiable evidence in our live Trust Center.
SOC 2 Type IIAudit in progress · Live Trust Center ↗Last updated: 8/30/2026
Our compliance status, security controls, penetration test reports, and policy documents are published in real time, monitored and powered by Oneleet. SOC 2 Type II audit in progress.
Data is hosted with reputable United States-based infrastructure providers. Your community's information stays in the US.
Our systems are designed to protect data in transit and at rest using widely adopted encryption methods.
Access is limited to those who need it to operate and support our services: role-based, least-privilege, with internal access controls.
SOC 2 Type II audit in progress. We align our practices with recognized security standards and monitor our environment on an ongoing basis.
Penetration test reports and policy documents are published through our live Trust Center, so you can verify rather than take our word.
We maintain processes to identify and respond to security incidents, and to communicate with affected customers consistent with law and contract.
EffiGov, Inc. ("EffiGov," "we," "us," or "our") is committed to protecting the information entrusted to us by the local governments and communities we serve. We use commercially reasonable, industry-standard administrative, technical, and physical safeguards designed to protect the information we handle against unauthorized access, use, or disclosure, and we review our practices as our business and the threat landscape evolve.
This page is provided for informational purposes only. It does not form part of any contract and does not create any representation, warranty, or commitment. Any binding security obligations are set out solely in the written agreement between EffiGov and its customers; in the event of a conflict, that agreement governs. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.
Our SOC 2 Type II audit is in progress. Our compliance status, security controls, penetration test reports, and policy documents are published in real time at our live Trust Center (trust.oneleet.com/effigov), monitored and powered by Oneleet.
Data is hosted with reputable United States-based infrastructure providers. EffiGov is headquartered in the US and serves US local governments.
Our systems are designed to protect data in transit and at rest using widely adopted encryption methods.
We seek to limit access to information to those who need it to operate and support our services, applying role-based access on a least-privilege basis together with internal access controls.
We maintain internal processes intended to help us identify and respond to security incidents. Where an incident affects a customer, we intend to communicate with that customer consistent with applicable law and the terms of our written agreement with them.
Yes. Policy documents and penetration test reports are available through our live Trust Center, and we work with customers' procurement and IT teams during security review. Contact founders@effigov.com.
Email founders@effigov.com. If you believe you have found a security issue, please include enough detail for us to reproduce and investigate it.
If you believe you have found a security issue, or you have a question about our practices as part of a vendor review, contact us and we will look into it.
founders@effigov.com