NPDESTracker

Security

Security posture, written plainly.

NPDESTracker is browser-based compliance software for municipal stormwater programs. This page summarizes how the service is built, accessed, and operated, with no marketing gloss.

Have a security questionnaire?Email us directly

Overview

An honest summary.

NPDESTracker is cloud-hosted, browser-based software. You access it through a standard web browser over HTTPS. Nothing is installed as a desktop application. Application checks and database row-level policies scope supported customer records to an agency tenant.

We do not currently hold third-party certifications such as SOC 2 or ISO 27001, and we don't claim them. What we do have is a clear architecture, an accountable team, and direct answers to the questions your IT and procurement teams are going to ask. If we commit to a control, we'll document it. If we don't have one, we'll tell you.

The sections below cover how access, data, and operations are handled today. Agencies connecting their own ArcGIS organization should also read ArcGIS integration and security, which covers named-user sign in, the read-only boundary on your GIS content, and where each kind of data is stored. For the operational side of the relationship (onboarding, day-to-day data handling, and what happens if you leave), see how it works.

What this page is (and isn't).

This is a public summary and a starting point for procurement and IT review. It is not a certification, audit report, penetration test, or contractual control schedule. Send the requirements that matter to your agency and we will confirm the current implementation, gaps, and any contractual commitments in writing.

01 · Authentication

Signed in. Scoped. Session-aware.

Each user signs in through the application's managed authentication service and has a role inside an agency tenant. The production application is served over HTTPS. Session lifetime, password recovery, and sign-out behavior are provided through the authentication service and application code.

  • Per-user named accounts. No shared credentials across staff.
  • Application roles inside each tenant (administrator, coordinator, inspector, viewer)
  • HTTPS for the production application
  • Password recovery through the managed authentication service
  • Explicit sign-out and provider-managed session handling
  • Authentication requirements beyond this baseline are confirmed during procurement review

02 · Tenant isolation

Your data belongs to your agency. Full stop.

NPDESTracker is a multi-tenant platform. Application checks and database row-level policies scope supported customer records to an agency tenant. Tenant isolation is covered by repository tests, but a public summary is not a substitute for an agency security assessment; current coverage for the modules in scope is confirmed during procurement review.

  • Tenant scoping and row-level policies for supported customer tables
  • User profiles associated with an agency tenant
  • An isolated public demo tenant with fictional data. Dashboard, My Work, Coordinator, Inspections, Tasks, and Map are unlocked; only Map is interactive. Messages & Notices, Annual Reporting, write, email-delivery, and agency-submission actions are locked.
  • Data ownership remains with the agency at all times
  • No cross-tenant aggregation, benchmarking, or resale of customer data. Operational analytics such as MS4 Metrics, the audit log workspace, IDDE response timelines, and readiness rollups run on a single tenant's own records.
  • Exports available in supported formats for modules included in the order
  • Evaluation-workspace export and deletion timing defined in the applicable order form

03 · Audit & traceability

Attribution on key workflows.

Selected compliance and reporting workflows record user and timestamp attribution. Audit coverage varies by module and action. Agencies with specific retention, export, or access-log requirements should identify them during procurement review so the current implementation can be confirmed in writing.

  • User and timestamp attribution on supported key records and reporting actions
  • Reporting audit events for supported year-state, evidence-link, and answer changes
  • Module-specific audit and export coverage confirmed for the purchased scope
  • No claim that every field or infrastructure event is captured in one universal audit log

04 · Hosting & infrastructure

Built on infrastructure your IT team already knows.

NPDESTracker uses managed cloud services for application hosting, authentication, database, and file storage. Provider controls and service-plan details can change, so encryption, backup, recovery, retention, and regional requirements are confirmed against the active production configuration during procurement review.

  • Production application served over HTTPS
  • Managed authentication, database, and file-storage services
  • Provider security and encryption documentation available during vendor review
  • Backup, point-in-time recovery, retention, and restoration commitments are not implied by this page and must be stated in the order form
  • Administrative access is limited to authorized operational needs

05 · Connected ArcGIS integration

Read-only against your ArcGIS, with no credential to hand over.

Agencies that connect their ArcGIS organization get a named-user OAuth connection: a staff member signs in with their own ArcGIS account and NPDESTracker reads the content that account can already see. NPDESTracker performs no writes against your ArcGIS content, so it cannot edit, publish, re-share, or delete authoritative GIS data. The full posture is on the ArcGIS integration and security page.

  • Named-user OAuth sign in. No ArcGIS password, API key, client secret, or shared service account is collected from your agency.
  • The long-lived refresh credential stays on the server and is never sent to the browser.
  • No feature edits, attachment changes, item administration, sharing changes, publishing, or web map saves against your ArcGIS content.
  • An automated code inventory and a runtime check must both report zero write calls before a release ships.
  • Each connection is keyed to one user in one agency workspace; identity is resolved on the server and never accepted from the browser.
  • An administrator can confirm the expected ArcGIS organization; a connection from a different organization fails closed with a recovery path.
  • Removing the application approval or disabling the account in ArcGIS ends what NPDESTracker can read.

06 · Secure development

Repository checks and explicit limits.

The repositories include automated tests for tenant-sensitive application behavior and checks for public-site security headers, source maps, and secret-shaped strings. These checks reduce specific risks; they are not a third-party certification, penetration test, uptime commitment, or guarantee that a release is vulnerability-free.

  • Automated repository tests for defined application and public-site controls
  • Secret-shaped string and source-map checks on the marketing-site build
  • Security headers configured for the deployed marketing site
  • Internal administration protected by application authorization checks
  • Dependency and vulnerability response handled as maintenance work without a public remediation-time guarantee
  • Responsible disclosure contact for reporting suspected vulnerabilities
  • Procurement questions answered directly; supporting material shared when it exists and is appropriate

07 · Security contact

How to reach us about a security concern.

If you believe you've found a security issue in NPDESTracker, the marketing website, or the application, please reach out so we can investigate. We treat well-intentioned reports as collaboration, not as adversarial.

  • Email admin@npdestracker.com with "Security" in the subject line
  • Include enough detail to reproduce the issue, but avoid sharing exploitation steps publicly
  • We will acknowledge receipt and follow up with next steps
  • If a customer suspects unauthorized access, email promptly so the available application and provider records can be reviewed

Have a procurement questionnaire?

Send us your security assessment, RFP requirements, or vendor questionnaire. We respond to public-sector due diligence and will provide what we can, and be straightforward about what we can't.