Security and access

Built for a public body’s records.

The controls on the portal itself are as plain as the controls on the ledger. Here is what a business office or an IT director will want to know before anyone is invited.

Invitation only

Nobody can create an account. A district administrator or Stoner Advisory Group invites each named user, and seats are capped per district.

No passwords

Sign-in is a six-digit code sent to the invited email address, with SMS as a backup channel. There is no password to phish, reuse or reset.

Roles

Board viewers see the board screens. Finance viewers see the drill-down: commitments, payments, vendors, reconciliation, documents. District administrators manage their own seats.

Every view logged

Who viewed and exported what, and when, is recorded for the district. Every page and every PDF carries a per-viewer watermark.

Your data stays yours

The ledger is built from your own records and is returned on request and at the end of the program. Real district data is never used in demonstrations; the demonstration district is fictional.

Hosting and backups

Hosted on Cloudflare with a strict content-security policy, HTTPS only, and daily exports of the database. Documents and exports are generated on demand and expire.

Accessibility

Held to the standard districts are held to.

Public bodies must meet WCAG 2.1 AA for their web content under the ADA Title II rule, and are told to require it of their vendors. This site and the portal are built and tested to WCAG 2.2 AA: keyboard operation, visible focus, 24-pixel targets, text alternatives on every chart, and automated checks on every release.

Read the accessibility statement →

Questions for your IT director?

Send them over. We answer security questionnaires as part of the engagement.