SPARK
Security
Open Desk holds Right-to-Know files for local agencies. This page says where that data lives and who can see it. It is a description of the product, not a security audit and not legal advice.
Where data lives
The application runs on Render in the United States, Ohio region (us-east-2). The database is PostgreSQL 17 on Render managed Postgres, with encryption at rest, daily backups, and 3 day point-in-time recovery on the current Hobby workspace. Uploaded files, including the original request and letter PDFs, are on an encrypted Render persistent disk with daily snapshots.
One agency cannot see another
Every agency shares one database, and PostgreSQL row-level security limits each session to that agency. A custodian sees requests they were asked about. A solicitor sees an agency only after that agency grants the login, and only the requests assigned to them or flagged for legal review. The application role cannot delete requests, documents, or the audit log.
Letters and the audit trail
A letter marked sent is frozen. The audit log is append-only. Sign-in is a one-time email link, not a password. The link expires in 15 minutes and works once.
Separate from Open Docket
Open Docket is the requester-side product. Open Desk does not write agency files into Open Docket, and it does not read Open Docket requests to fill an agency log. The two products do not share a database.
Who at SPARK can look
There is no web screen that lists every agency. Creating an agency is an administrative job in the private network. The people who operate the Render account can reach the database the way any host can reach its own database. That access is not a feature of the product, and it is not given to Open Docket.
There are two switches. Staff email (sign-in links, invitations, and reminders) stays off until it is turned on for the service. Letters to requesters stay off until that agency turns them on. Until a letter can be emailed, it is a PDF to print and mail. While staff email is off, sign-in links are printed to the server log instead of being sent.
What this page does not claim
Open Desk has not had an independent penetration test. Uploads are not scanned for malware yet. Backups are the Render window described above, and a restore drill should be run before an agency relies on the product for a real deadline. Questions: support@rtkldecisions.com.