Security
Your county's data stays your county's
SentraDeed handles owner names, mailing addresses and recorded document images. Here is how the service protects them, written for county IT and security reviewers.
Security controls
Hosting and data residency
SentraDeed runs on Amazon Web Services in the us-west-2 (Oregon) region, with U.S. data residency. The application and database run in private network subnets; only the load balancer is public. Daily files arrive by SFTP through AWS Transfer Family, and email is sent through Amazon SES.
Encryption
HTTPS only, with TLS 1.2 or later and HSTS on the web apps. The database, file storage and backups are encrypted at rest with AWS KMS keys, and secrets are held in a secrets manager, never in source code.
Subscriber email encryption
Subscriber email addresses are encrypted in the application with a per-county key and looked up by a keyed hash.
Tenant isolation
Every county-owned table carries a county ID and every query filters by it. PostgreSQL row-level security enforces the same boundary inside the database, and an automated cross-tenant test checks that one county cannot read another's data.
Least-privilege database role
The application connects as a role that is not a superuser, does not own the tables and cannot bypass row-level security.
Staff sign-in and roles
Staff sign in with single sign-on through the county's identity provider (SAML or OIDC), with multi-factor authentication for any account that is not federated. Access is role-based (Recorder admin, Recorder staff, Assessor submitter, Auditor, vendor support), with a 30-minute idle timeout and a 12-hour maximum session.
Append-only audit log
Every mutating action is written to an append-only log. Entries are hash-chained, so a changed or deleted entry breaks the chain, and auditors can verify a date range.
Logging policy
Application logs carry record IDs only. Owner names, mailing addresses and subscriber emails are not written to logs at INFO level or above.
Document image retention
Recorded document images used to read APNs are purged 30 days after receipt by default, configurable per county.
Accessible notices
Every notice PDF is tagged to PDF/UA-1 and validated with veraPDF, and every staff console and resident portal page passes automated axe-core checks.
Access control
Who can do what
Roles are assigned per county by the county's Recorder admin.
| Permission | Recorder admin | Recorder staff | Assessor submitter | Auditor | Vendor support |
|---|---|---|---|---|---|
| View dashboard, documents, runs | Yes | Yes | Files only | Yes | Yes |
| Upload Recorder file | Yes | Yes | No | No | Yes |
| Upload Assessor file | Yes | No | Yes | No | Yes |
| Work exceptions | Yes | Yes | No | No | No |
| Approve batch | Yes | No | No | No | No |
| Mark batch mailed | Yes | Yes | No | No | No |
| Void notices | Yes | No | No | No | No |
| Settings, templates, users | Yes | No | No | No | No |
| View audit log | Yes | No | No | Yes | Yes |
Vendor support access across counties is read and operations only, and every such access is audited.
Data handling
Retention, transfer and residents
- Other records
- Retention for raw files, notices and the audit log is set with each county to match its records-retention schedule.
- Sub-processors
- Third parties that process county data are listed on the Sub-processors page.
- File transfer
- Daily Recorder and Assessor files arrive by SFTP through AWS Transfer Family (SSH keys, one account per county) or by upload in the staff console over HTTPS.
- Resident portal
- Collects only an email address, the parcels or names being watched and a language preference. Alerts never include owner names, mailing addresses or document images. See Disclosures.
- OCR
- APN reading from document images uses U.S.-hosted OCR services only. Uncertain readings go to staff; on the synthetic test set, image-mode OCR produced zero wrong-parcel notices.
- AI Assist
- Optional and off by default; counties turn it on. APN second reader: evaluated on the synthetic test set (98 deed images across 7 scan variants) it read 98/98 APNs correctly, invented none on pages without an APN, and produced 0 wrong-parcel notices through the matching rules. It can only confirm an OCR reading it matches exactly; it never decides alone and never clears fraud signals. Recommended rollout: shadow, then suggest, then corroborate, after a trial on the county's own images. Exception copilot (document-type and government-grantee suggestions): spot-checked and still under evaluation; suggestions are advisory, staff apply them, and anything that would mean "no notice" is never pre-selected. County data is not used to train models. See Sub-processors.
Accessibility
Accessibility, checked automatically
The staff console, resident portal and emails meet WCAG 2.1 AA in automated axe-core checks on every page, with zero violations; an automated keyboard-only test covers resident sign-up, and every notice PDF is validated as PDF/UA-1 with veraPDF. See the Accessibility Conformance Report (VPAT 2.5).
Report a vulnerability
Found a security issue?
Email [email protected] with a description and steps to reproduce. Please don't access data that isn't yours or disrupt the service while testing. We'll acknowledge your report and keep you informed as we fix it.
A written security overview for county reviewers is available on request.
See it run on your files
We'll walk your Recorder and Assessor teams through a full cycle on a few days of your own exports: intake, matching, exceptions, a print-ready batch and the resident portal.