Security and access
Built for a public body’s records.
The controls on the portal itself are as plain as the controls on the ledger. Here is what a business office or an IT director will want to know before anyone is invited.
Invitation only
Nobody can create an account. A district administrator or Stoner Advisory Group invites each named user, and seats are capped per district.
No passwords
Sign-in is a six-digit code sent to the invited email address, with SMS as a backup channel. There is no password to phish, reuse or reset.
Roles
Board viewers see the board screens. Finance viewers see the drill-down: commitments, payments, vendors, reconciliation, documents. District administrators manage their own seats.
Every view logged
Who viewed and exported what, and when, is recorded for the district. Every page and every PDF carries a per-viewer watermark.
Your data stays yours
The ledger is built from your own records and is returned on request and at the end of the program. Real district data is never used in demonstrations; the demonstration district is fictional.
Hosting and backups
Hosted on Cloudflare with a strict content-security policy, HTTPS only, and daily exports of the database. Documents and exports are generated on demand and expire.
Accessibility
Held to the standard districts are held to.
Public bodies must meet WCAG 2.1 AA for their web content under the ADA Title II rule, and are told to require it of their vendors. This site and the portal are built and tested to WCAG 2.2 AA: keyboard operation, visible focus, 24-pixel targets, text alternatives on every chart, and automated checks on every release.
Questions for your IT director?
Send them over. We answer security questionnaires as part of the engagement.