OpenCAMA IQ is built so the people who scrutinize you most — your CISO, your county auditor, an appeals board, a public-records request — find exactly what they expect: a complete, defensible trail and a platform that holds your data, never holds it hostage.
Assessment is a fiduciary act. The platform treats the audit trail as a first-class part of the data model, not an afterthought you have to remember to enable.
Built for the moments that matter: defending an appeal, answering a FOIL / public-records request, or reconstructing a contested assessment line by line.
Controls are wired into how data is stored and served, so a permission can't be bypassed by hitting a different screen or endpoint.
Authenticate through your existing Azure Active Directory — MFA, conditional access, and offboarding flow straight from your identity provider. No separate password store to manage.
Granular roles plus field-level rules are enforced at the data layer, so what a user can see and change is consistent across every dashboard, search, and export.
Connection strings, API keys, and storage credentials live in a managed secrets vault — never in source, never in config files checked into a repo.
All traffic is encrypted in transit. No mixed-content paths, no plaintext fallbacks.
PostgreSQL row-level security scopes records to the right jurisdiction and role at the database itself — the last line of defense if anything above it is misconfigured.
The public portal holds no database credentials. It talks only to a gateway — so the citizen-facing site has nothing for an attacker to steal.
The certifications your procurement, legal, and accessibility reviewers ask for by name, each labelled with its real status rather than its ambition. Nothing here is claimed before it is earned.
COD, PRD, and PRB are computed directly in the valuation statistics, so every model run and every certified roll arrives with its ratio study attached.
Secrets management, managed identity, audit-by-default, and environment isolation are built to the NIST 800-53 control framework. This alignment is self-assessed today, not yet attested by a third party.
Conformance verification is underway for the public portal and every staff application, with automated accessibility checks gating the build pipeline. A VPAT/ACR on the ITI template is in preparation.
The baseline most county IT shops require. The audit window is designed to open alongside a live pilot, so the attestation matures with a real deployment rather than ahead of one.
Authorization for state and local government deployment, sequenced after SOC 2 Type II and built on the same NIST 800-53 control alignment already in the architecture.
Individual professional certifications across the engineering team, principally on the Microsoft platform. These were earned individually rather than through a corporate credentialing program.
We would rather tell you this plainly than let a procurement review discover it. A certification earned ahead of need attests to paperwork; one earned alongside a live government deployment attests to practice. If your jurisdiction weights formal certification differently, the SOC 2 timeline can be accelerated.
Proprietary incumbents make leaving expensive on purpose. We do the opposite — and we put it in the contract.
The platform is open. No black boxes deciding your values, no opaque data formats you can't read without the vendor — your data and every integration surface are documented and reachable.
Your full dataset — parcels, values, history, exemptions — exports in documented, standard formats whenever you want it.
A defined, low-friction off-ramp written into the agreement. Leaving is your right, not a renegotiation.
Deployed in US regions of either major cloud, so residency and jurisdiction questions have a straight answer for your county counsel.
Runs on either major cloud, inheriting the provider's compliance, redundancy, and security posture — not a self-hosted stack you have to vouch for alone.
You own the data and the right to take it with you. Hosting is a service we provide, not leverage we hold.
Explore the citizen-facing side on the public portal page, or see how it all fits together on the platform overview.
Bring your CISO and your auditor. We'll walk through field-level logging, certified snapshots, the data-layer permission model, and the exit terms — on real screens.
Request a demo