NJTownWorks
Sign InDashboard
Privacy PolicyTermsDisclaimerAcceptable UseCookiesAccessibilitySecurityDPA

Security

Last Updated: July 29, 2026

Confidential municipal financial data deserves careful protection — and honest answers about how it is protected.

NJTownWorks reads the documents your office already produces, runs a fixed set of finance tasks, and returns an import-ready file you review. Below is a plain, accurate description of the controls in place today. We describe what we actually do — not aspirations — because a security claim you cannot back is worse than none.

Where your data lives

NJTownWorks runs on established U.S. cloud infrastructure — Cloudflare (network and application delivery) and Supabase (database, authentication, and file storage), both operating in United States regions. These providers maintain their own independently audited data-center controls (physical access, monitoring, and environmental protection) as our sub-processors. Your documents are never stored on personal devices or public locations.

Encryption

In transit

Every connection between your browser and NJTownWorks is encrypted with HTTPS/TLS. The site is served only over HTTPS.

At rest

Documents and database records are encrypted at rest with AES-256 by our infrastructure providers' storage layer. (We do not currently add a separate application-managed encryption layer on top of this; if your office requires that, tell us and we will scope it.)

Tenant isolation — enforced at the database, not just the app

Each municipality's data is isolated from every other municipality. This is enforced at two layers:

  • Database row-level security (RLS). The database itself refuses to return one municipality's rows to a user who belongs to another — the rule lives in the database, so it holds even if application code has a bug.
  • A server-side tenant guard. Your municipality is determined on our server from your authenticated session, never from anything a document or a form field says. Uploaded files are stored in a private, per-municipality partition, and downloads use short-lived, single-purpose links scoped to your own municipality.

We keep an automated cross-tenant test in our codebase that must pass before changes ship, specifically to prove one municipality cannot reach another's data.

Your documents

Files you upload are used only to run the task you chose, and are held in your municipality's private storage partition. They are never made public and never shared with other municipalities. We validate uploads (file type and size) before processing. If you would like a document or a batch removed, contact us and we will delete it; we are also adding a self-service delete and an automatic retention window — see “What we are still building” below.

Authentication and access

Municipal users sign in without a password. We send a one-time code (or a single-use link) to your work email — there is no password to guess, reuse, or leak. Sessions are cryptographically random and expire.

Our own staff access is restricted to a short, named allow-list of two people at a separate, non-advertised sign-in. Authenticator/passkey enrollment is available for staff accounts. Ordinary municipal accounts can never reach staff tools.

How we keep the numbers trustworthy

NJTownWorks does not let the AI free-hand your figures. Every dollar amount is computed and checked by deterministic code — reconciliations must tie to $0.00, and journal entries must balance (debits equal credits) — before any file is produced. The AI reads your documents and explains the result in plain English; it never invents a number. And nothing posts to your general ledger automatically: the output is a file you review and import yourself. You remain the responsible official.

Activity logging

Key events — sign-ins, task runs, staff actions, and escalations — are recorded so we can investigate questions and support your office. We are expanding this to a full per-document access trail (see below).

Reviewing our own changes

Changes go through automated tests and a security review before release. We monitor our dependencies for known vulnerabilities. The platform runs on edge infrastructure with a deliberately small surface area, and configuration secrets are stored as encrypted secrets, never in code.

What we are still building (so we can be honest about the gaps)

A security-minded office should ask what we do not yet have. Today we do not provide: automated malware scanning of uploads, a formal data-retention/auto-deletion schedule (deletion is currently on request), a full per-document access audit trail, or a third-party SOC 2 / StateRAMP attestation of NJTownWorks itself (our sub-processors hold their own SOC 2). These are on our roadmap; we would rather list them plainly than imply a control we have not built.

New Jersey breach notification

If a data breach affecting your information were confirmed, we would notify your municipality promptly and cooperate as required under New Jersey's data-breach notification law (N.J.S.A. 56:8-163). NJTownWorks is a product of JRSB Solutions, LLC.

Reporting a security issue

If you discover a vulnerability, please report it responsibly to:

NJTownWorks — Security
Email: [email protected]

We will acknowledge your report within 1 business day and work with you in good faith to understand and address any valid concern.

Product

  • Dashboard
  • Security

Legal

  • Privacy Policy
  • Terms of Service
  • Acceptable Use
  • Cookie Policy

Compliance

  • Accessibility
  • Data Processing

Contact

  • [email protected]

NJ Town Works — a product of JRSB Solutions, LLC. © 2026 JRSB Solutions, LLC. All rights reserved.

Built for New Jersey's 564 municipalities.