title ii readiness for public entities

10,184 sites in the Index, last scanned August 2, 2026. days to April 26, 2027 days to April 26, 2028

Security

What CivicBinder stores, who else processes it, and how to report a vulnerability.

Reporting a vulnerability

Email hello@thecompound.tech. Include the URL, what you did, and what you saw. There is no bounty and no NDA to sign. We will confirm receipt, and we will tell you what we changed.

The same address, with a machine-readable expiry, is published at /.well-known/security.txt under RFC 9116.

Accounts

CivicBinder has no user accounts. There is nothing to sign in to, no password to reset and no session to steal, and a build gate fails the deploy if an authentication route ever appears in this repository while this page still says otherwise.

What is stored

  • If you request a free report, the entity name, the site address and the contact details you enter are emailed to us so that somebody can answer you
  • The public site address you enter into the scan is fetched and read — the way any visitor's browser would — and nothing about that fetch is stored
  • Anonymous usage analytics — page views and clicks. Form inputs are masked in session recordings and no profile is created for a visitor who never identifies themselves

Who else processes data

  • Google Workspace — delivers the report request to our own mailbox over SMTP
  • Supabase — the database behind the Title II domain pages this site publishes
  • PostHog — anonymous product analytics, proxied through this domain
  • Vercel — serves this site and holds its access logs

Also true

  • There is nothing to sign in to on this site. A request is an email to us, not an account.
  • No payment is taken on this site at all — there is no checkout route in this product, which is a fact a build gate re-checks rather than a claim made here.
  • The scan only ever reads pages that are already public. It does not sign in to anything and it does not submit any form.

CivicBinder is built and run by Compound Labs. The declarations on this page are part of this product's own configuration and are re-checked at every deploy against the repository they describe: a product that claims to have no accounts and ships an authentication route fails the build, and so does one that takes payment without naming its payment processor here.