At OpenGov, we treat the security and reliability of our cloud platform and that of the data it hosts with utmost importance. Building that level of trust with our customers is a key priority for us. Learn about our extensive security and reliability practices and comprehensive compliance controls on this page. Contact us at trust@opengov.com for additional information, reporting vulnerabilities, or any other concerns related to assurance of OpenGov’s cloud platform.
Self-Assessments
We are working on our security compliance. We can provide completed questionnaires upon request.
Policies
Our policies are currently under review and revision. Please contact us if you would like additional information in the meantime.
Risk Management
We have a dedicated team that manages security risks. We are happy to provide more details about our risk management practices upon request.
Asset Management
We have strict asset management policies in place to ensure that all assets are accounted for and secure.
Change Management
We have a change and configuration management process in place to ensure that changes are properly reviewed and approved.
Subprocessors
OpenGov Trust Center Updates
Security advisory: Phishing emails impersonating OpenGov
OpenGov is aware that malicious third parties may occasionally impersonate legitimate emails in an attempt to compromise recipients. We have received reports of phishing emails that falsely claim to come from OpenGov or from an "OpenGov Procurement Portal," typically asking the recipient to download a file or follow a link to a third-party website.
This activity originates from outside parties. There is no evidence that OpenGov systems or customer data have been compromised. These messages are not sent by OpenGov and do not come from OpenGov systems.
How to stay safe:
- OpenGov does not send emails that redirect you to third-party file-sharing or websites to retrieve OpenGov documents.
- Do not click links or download files from untrusted or unexpected sources.
- Be cautious of file-share notifications (for example, "you've been sent a file") that reference OpenGov or a procurement portal but come from an unfamiliar sender or domain.
- When in doubt, confirm directly with your trusted OpenGov contact before taking action.
- Report suspected OpenGov-related phishing to security@opengov.com.
- Also report the message to your own organization's IT/security team using your normal process.
We are working with affected customers and will update this notice if our assessment changes.








