NPDESTracker

How it works

How NPDESTracker works for your program.

Three questions come up in almost every procurement conversation: how does onboarding actually work, how is our data handled while we're using the product, and what happens if we leave. Here are the answers in plain language.

Have a procurement or IT question?Email us directly

01 · Getting started

Onboarding is light by default.

Most evaluation workspaces open the same way. A 30-minute kickoff call to confirm scope, agree on what the program is trying to evaluate, and walk through how the workspace will be set up. The evaluation starts with a workspace configured to your permit framework and a starter slice of your real data.

The data import is intentionally light. CSV templates for inspections, BMPs, sites, and outfalls. GeoJSON or shapefile imports for spatial layers from your existing GIS. We do not require you to map your full asset inventory before going live. Most cities are running on sample data within a week, then on a starter slice of their own data shortly after, with the rest coming in as the program runs.

What you do: provide the existing records you want to bring in, identify the inspectors and coordinators who need accounts, and confirm the modules in scope.

What we do: configure the workspace to your permit framework, walk you through the setup, set up user accounts, and stay reachable through the kickoff period. NPDESTracker is on the call and on email during the evaluation.

If your data needs more than the standard import, like a large historical migration or a complex GIS layer translation, we look at the actual data first and quote a written scope honestly. We do not sell implementation as a separate big-ticket service. The goal is to get you running on your own program, not to maximize billable hours. The full pricing posture is on the pricing page.

  • A 30-minute kickoff call to confirm scope and what success looks like at 60 days
  • An evaluation workspace configured to your permit framework and a slice of your real data
  • CSV templates for inspections, BMPs, sites, and outfalls
  • GeoJSON or shapefile imports for spatial layers from your existing GIS
  • User accounts for the inspectors and coordinators who need them
  • Direct implementation support during the evaluation period

02 · Data handling

Your data belongs to your agency.

Your agency's data lives inside its own logical tenant on managed cloud infrastructure. Application checks and database row-level policies scope supported customer records to that tenant. The production application is served over HTTPS. Provider, region, encryption, backup, recovery, and retention details are confirmed against the active production configuration during procurement review.

Who can access your data: the named user accounts for staff at your agency, plus a small number of authorized engineers on our side who maintain the platform. We do not browse customer data without a request from the customer, and we do not share customer data with anyone outside your authorized agency staff.

What we never do: sell your data to third parties, use your data to train AI or machine learning models, or share your data outside the agencies you have authorized.

Audit trail: supported key compliance and reporting workflows record user and timestamp attribution. Coverage varies by module and action, so specific retention and export requirements are confirmed for the purchased scope.

The full security posture, including infrastructure, secure development practices, and what we currently do and do not hold for third-party certifications, is on the security page.

  • Per-agency tenant scoping enforced at the database query layer
  • Production application served over HTTPS
  • Managed authentication, database, and file-storage services
  • Provider, region, encryption, backup, recovery, and retention details confirmed during procurement review
  • User and timestamp attribution on supported key compliance and reporting workflows

03 · If you leave

You can leave with your data, cleanly.

If an evaluation workspace does not convert, or an annual customer decides to move on later, the offboarding process is straightforward. Your data is yours throughout the relationship and yours after it ends. We are not going to make leaving harder than starting.

Exports happen at any time, not just at the end. CSV exports cover supported operational records, with broader spatial-format export support available during onboarding and support requests. PDF print-friendly views are available for finalized reports.

Offboarding itself: on notice from the agency, we coordinate a final export bundle, hand it over, and proceed with data deletion on the schedule defined in your contract. Most offboarding wraps cleanly within a defined window after the final bundle is delivered.

What we do not do: hold your data as leverage to extend the relationship, charge a separate fee for the final export, or strip metadata from records on the way out. Offboarding is part of the contract, not an upsell opportunity.

The point of writing this down publicly is that you can include it in procurement review with your IT or finance staff before you ever sign an evaluation agreement. There is nothing in the offboarding posture that we would not want a city attorney to read.

  • Data export at any time during the contract, not just at the end
  • CSV exports for supported operational records, with broader spatial-format export support available during onboarding and support requests
  • PDF print-friendly views for finalized reports
  • Final export bundle delivered as part of offboarding
  • Data deletion on the schedule defined in your contract
  • No proprietary lock-in, no retention as leverage

Questions we expect

Things procurement and IT typically ask.

Where is the data physically stored?

The production region and active managed-service providers are confirmed during procurement review. This public page does not create a contractual data-residency, backup, or recovery commitment; those requirements belong in the applicable order form.

Do you hold SOC 2 or ISO 27001?

We do not currently hold those certifications, and we do not claim them. What we do have is a clear architecture, an accountable team, and direct answers to procurement questionnaires. If a control is in place, we document it. If it is not, we say so. The full posture is on the security page.

Can we get our data out before signing anything?

The public sample workspace tour is read-only and runs against fictional data only, so there is nothing of yours to export yet. During an evaluation workspace, you can export at any time. The export formats and fields are documented in the platform, not gated behind a support request.

What if our IT team needs a security questionnaire filled out?

Send it. We respond with the controls we can confirm, the gaps we know about, and the requirements that would need a written commitment. Supporting material is shared when it exists and is appropriate.

Who do we email with questions during an evaluation workspace?

Guided end-to-end. Evaluation workspaces are not handed off to a support queue. The same NPDESTracker team that runs the kickoff call answers procurement questions, IT questions, and stormwater coordinator questions during the 60-day window.

Bring this page into the procurement review.

The point of writing this down is so your IT and procurement reviewers can read it before any call. If something is unclear or your team needs more depth, NPDESTracker reads every email at admin@npdestracker.com.