What your IT, security, and procurement teams will want to know.
PermitDesk handles permit and license applications, applicant documents, and fee records for local governments. This page states plainly how the system is built to protect that data, where AI does and does not act, who owns what, and what happens when things fail. The technical guide carries the implementation detail.
Security overview
The controls below describe how the system is designed and operated. Where we say "designed to," that reflects control intent and implementation, not a third-party certification, which we do not claim here.
- Encryption in transit and at rest. The portal and APIs run over TLS, file exchange runs over SFTP, and data stores and backups are designed to be encrypted at rest with keys held in a managed secrets store.
- Role-based access. Least-privilege roles scope what each person can see and do: an intake clerk, a department reviewer, an inspector, and an auditor each get only their slice. Access is scoped to a single jurisdiction, with no cross-jurisdiction visibility.
- Audit logging. Every submission, classification, completeness result, routing decision, fee calculation, human action, and status change is written to an append-only log, so any permit can be traced back to the full record behind it.
- Applicant-PII data minimization. An application collects only what that permit or license type requires. Personal information a type does not need is never requested, and applicant data is never used for advertising.
Where AI sits
PermitDesk uses AI for three specific jobs: it checks each submittal for completeness against the checklist for its permit type, it classifies and routes applications to the right departments, and it writes plain-language guidance so applicants understand exactly what is missing or wrong.
The boundary around those jobs is hard:
- It never issues or denies a permit. Every AI output is a proposal a staff member confirms, changes, or overrides.
- Every automated action is logged, including the reason, alongside every human action.
- Determinations belong to staff. Approvals and denials are made by your reviewers, always.
- Applicant data never trains models. Applications and documents are processed solely to provide the service to your jurisdiction.
Data ownership and export
Your jurisdiction owns its data. That is not a slogan; it has three concrete consequences:
- Full export, any time. Applications, documents, fee records, and the audit log are exportable in standard, documented formats whenever you ask, not only at contract end.
- No lock-in by format. Exports use formats your records and finance systems can already consume, so leaving is a data transfer, not a rescue project.
- Defined disposal at contract end. After your final export is confirmed, your data is securely disposed of on a defined schedule, with the disposal recorded.
Reliability
A permitting system's worst failure mode is a lost application, because the applicant finds out weeks later at the counter. PermitDesk is built around not letting that happen:
- Every submission is acknowledged at intake and tracked to a disposition. Nothing enters the system without a record that it did.
- Monitored pipelines with alerting. Intake and data-exchange pipelines are monitored, and failures raise alerts to our team.
- A failed intake is a ticket, never a gap. If a transfer or ingest fails, it becomes a tracked issue we resolve, not a silent hole an applicant discovers at the counter.
Vendor packet
Procurement and InfoSec reviews should not stall on paperwork. The following are available on request, at any stage of your evaluation:
- Vendor security assessment responses
- W-9
- Certificates of insurance
- References
Email hello@trypermitdesk.com for the packet, or bring your own questionnaire and we will complete it.
About the company
PermitDesk is built and operated by JS Technology Solutions, Inc., an Illinois-registered technology firm with hands-on experience delivering secure intake, routing, and document-validation systems in demanding public-sector and enterprise billing environments. Company site: www.jstech-inc.com. Contact: hello@trypermitdesk.com.
Put your security review on the calendar early.
Bring IT and procurement to the demo. We would rather answer the hard questions in week one than in week nine.
Request a demo