Built on a foundation of security and transparency.
4,500+
Government Agencies Served
SOC 2
Type II Compliance Program
TLS 1.2+
Encryption in Transit
System Description
In-Scope Applications & Services
The following Neumo products and services are included within the boundaries of our security program and SOC 2 compliance scope.
- Revenue Compliance Platform
Tax & licensing compliance, short-term rental enforcement, compliance auditing, and unclaimed property management. - Justice Solutions
Court case management, jury administration, and probation tracking systems for state and local agencies. - Public Administration
Land records, vital records, public search, and pension administration platforms. - Payment Solutions
Neumo Payments and revenue management tools for government collections and constituent payments. - DMV Services
Kiosk, testing & certification, and fulfillment services for DMV modernization. - Neumo Platform
Shared platform infrastructure including reporting & analytics, forms, digital processing, ID verification, eSignatures, and alerts. - New Hire Reporting Pipeline
State new hire electronic reporting services processing employer and employee PII data on behalf of Paychex for multi-state agency submission.
System Boundary
What Is Inside and Outside Our Scope
Our security program and SOC 2 scope covers the systems, infrastructure, and processes described below.
System Boundary Definition
|
Included in Scope
|
Excluded from Scope
|
Security Commitments
How We Protect Your Data
Neumo makes the following security commitments to all customers and the government agencies we serve.
- Encryption in Transit
All data transmitted over public networks is encrypted by default using TLS 1.2 or higher. File transfers use SFTP or FTPS. Plain FTP and unencrypted HTTP are not permitted. - Encryption at Rest
Data stored on Neumo-managed systems is encrypted at rest. Laptops and workstations accessing production systems use full-disk encryption (BitLocker). - Access Control
Access to production systems follows the principle of least privilege. User accounts are reviewed periodically and access is revoked promptly upon termination. - Account Lockout Policy
System accounts are automatically locked after a defined number of consecutive failed login attempts to protect against brute-force attacks. - Backup & Recovery
Production data is backed up on a defined schedule via Microsoft Azure Backup. Automated alerts notify IT personnel of any backup failures for prompt investigation. - Mobile Device Management
Mobile devices and laptops that access company data are enrolled in a Mobile Device Management (MDM) solution with remote wipe, passcode enforcement, and encryption required. - Incident Response
Neumo maintains a documented incident response plan. Security incidents are investigated, contained, and resolved in a timely manner. Affected customers are notified per contractual and legal obligations. - Change Management
Code and configuration changes follow a defined change management process including review, testing in a separate environment, and approval before promotion to production. - Security Awareness Training
All Neumo employees complete security awareness training annually, covering data handling, phishing, password hygiene, and acceptable use policies.
Audit Type: SOC 2 Type II
SOC 2 Type II Compliance
Neumo undergoes an annual SOC 2 Type II audit conducted by an independent third-party auditor. The audit evaluates the design and operating effectiveness of our security controls against the AICPA Trust Services Criteria.
Security questions or concerns?
Contact our security team directly for vulnerability disclosures, report requests, or security due diligence inquiries.