digital padlock cybersecurity network data protection

Security & Compliance

Neumo is committed to protecting the data of the government agencies and communities we serve. This page describes our in-scope systems, security boundaries, and the commitments we make to every customer.
Scroll Down

Built on a foundation of security and transparency.

4,500+

Government Agencies Served

SOC 2

Type II Compliance Program

TLS 1.2+

Encryption in Transit

software developer at desk with code on monitor

System Description

In-Scope Applications & Services

The following Neumo products and services are included within the boundaries of our security program and SOC 2 compliance scope.

  • Revenue Compliance Platform
    Tax & licensing compliance, short-term rental enforcement, compliance auditing, and unclaimed property management.
  • Justice Solutions
    Court case management, jury administration, and probation tracking systems for state and local agencies.
  • Public Administration
    Land records, vital records, public search, and pension administration platforms.
  • Payment Solutions
    Neumo Payments and revenue management tools for government collections and constituent payments.
  • DMV Services
    Kiosk, testing & certification, and fulfillment services for DMV modernization.
  • Neumo Platform
    Shared platform infrastructure including reporting & analytics, forms, digital processing, ID verification, eSignatures, and alerts.
  • New Hire Reporting Pipeline
    State new hire electronic reporting services processing employer and employee PII data on behalf of Paychex for multi-state agency submission.

System Boundary

What Is Inside and Outside Our Scope

Our security program and SOC 2 scope covers the systems, infrastructure, and processes described below.

System Boundary Definition

Included in Scope
  • Cloud infrastructure hosted on Microsoft Azure
  • Neumo-developed application code and services
  • Data transmission pipelines (SFTP, FTPS, HTTPS)
  • Production and test server environments
  • Employee workstations accessing production systems
  • Third-party sub-processors with data access
  • Backup and disaster recovery systems
  • Access management and identity controls
Excluded from Scope
  • Customer-owned infrastructure and networks
  • Third-party payment processors (PCI DSS scoped separately)
  • End-user devices not managed by Neumo
  • Public internet infrastructure outside Neumo control
  • Customer identity provider systems

Security Commitments

How We Protect Your Data

analyst silhouette reviewing data dashboards screens

Neumo makes the following security commitments to all customers and the government agencies we serve.

  • Encryption in Transit
    All data transmitted over public networks is encrypted by default using TLS 1.2 or higher. File transfers use SFTP or FTPS. Plain FTP and unencrypted HTTP are not permitted.
  • Encryption at Rest
    Data stored on Neumo-managed systems is encrypted at rest. Laptops and workstations accessing production systems use full-disk encryption (BitLocker).
  • Access Control
    Access to production systems follows the principle of least privilege. User accounts are reviewed periodically and access is revoked promptly upon termination.
  • Account Lockout Policy
    System accounts are automatically locked after a defined number of consecutive failed login attempts to protect against brute-force attacks.
  • Backup & Recovery
    Production data is backed up on a defined schedule via Microsoft Azure Backup. Automated alerts notify IT personnel of any backup failures for prompt investigation.
  • Mobile Device Management
    Mobile devices and laptops that access company data are enrolled in a Mobile Device Management (MDM) solution with remote wipe, passcode enforcement, and encryption required.
  • Incident Response
    Neumo maintains a documented incident response plan. Security incidents are investigated, contained, and resolved in a timely manner. Affected customers are notified per contractual and legal obligations.
  • Change Management
    Code and configuration changes follow a defined change management process including review, testing in a separate environment, and approval before promotion to production.
  • Security Awareness Training
    All Neumo employees complete security awareness training annually, covering data handling, phishing, password hygiene, and acceptable use policies.

Audit Type: SOC 2 Type II

SOC 2 Type II Compliance

Neumo undergoes an annual SOC 2 Type II audit conducted by an independent third-party auditor. The audit evaluates the design and operating effectiveness of our security controls against the AICPA Trust Services Criteria.

Request SOC 2 Report

Security questions or concerns?

Contact our security team directly for vulnerability disclosures, report requests, or security due diligence inquiries.

[email protected]

This site uses cookies. By continuing to browse this site, you agree to this use.

Privacy Policy