Compliance
Security certifications, data protection policies, and regulatory compliance documentation for CityDesk.AI.
SOC 2 Alignment for AI Agents and Chatbots for Municipalities
CityDesk supports SOC 2 controls related to retention and disposal, focusing on C1.2 (Confidential Information Disposal) and P5.1 (Data Retention). It outlines configurable retention with automated enforcement, deletion logging via a retention audit trail, and legal holds, along with the evidence a municipality can request during a vendor assessment.
Read moreRetention Audit Trail for AI Chatbots and Agents for Cities and Towns
CityDesk maintains a retention audit trail that records every deletion performed under retention policies to prove compliant disposal and confirm legal holds were honored. It captures details like record type, creation and deletion timestamps, applicable retention period, the job that triggered deletion, and any items skipped due to holds for use in audits and public records responses.
Read moreNIST 800-53 Alignment for AI Chatbots and Agents for Municipalities
This document explains how CityDesk aligns with key NIST 800-53 controls, focusing on AU-11 (Audit Record Retention) and SI-12 (Information Management and Retention). It highlights CityDesk’s tamper-evident audit trail, configurable retention for different record types, archiving of audit logs before deletion, and legal holds, and lists the evidence municipalities can request to demonstrate compliance.
Read moreLegal Holds for AI Chatbots and Agents in Municipal Governments
Legal holds prevent records from being deleted when preservation is required for litigation, public records requests, regulatory oversight, or internal investigations. They can apply to conversations, uploaded files/knowledge base documents, audit logs, or broader scopes like specific projects or departments, and both creating and releasing a hold are logged before normal retention resumes.
Read moreData Retention Policies for Municipal Chatbots and Agents
CityDesk lets municipalities configure how long different record types are kept—such as conversation records, uploaded files/knowledge base documents, and audit logs—with retention periods that can vary by department or project. Retention is enforced on a schedule, with audit logs archived before deletion and each deletion recorded, while legal holds can pause retention when preservation is required.
Read moreAudit Trail for AI Chatbots and Agents
CityDesk keeps a tamper-evident, append-only audit trail so municipal staff can see what actions occurred, when, and by whom. It records activity such as user/admin actions, AI conversation activity, knowledge base access, retention setting changes, legal hold events, and retention deletions, with configurable retention and export options to support audits, investigations, and public records responses.
Read more