Skip to main content

    Government & federal data governance

    Last updated: June 3, 2026

    This page is written for government agencies, federal grant program officers, and procurement reviewers. It documents how Floodi handles data in public-sector and federally funded contexts. It complements the consumer-facing Privacy Policy and the Security Posture Overview.

    1. Data classification

    Floodi processes only public and low-sensitivity data: publicly published National Weather Service / NOAA alerts, USGS gauge readings, FEMA NFHL flood-zone geometry, and voluntarily submitted, public-safe community flood observations. Floodi does not store classified, controlled unclassified information (CUI), protected health information (PHI), or federal personally identifiable information beyond optional self-provided contact details for pilot partners.

    2. NIST-aligned control posture

    Floodi maps its controls to the NIST SP 800-53 / NIST Cybersecurity Framework control families relevant to a low-impact public data service:

    NIST familyFloodi implementation
    Access Control (AC)Supabase row-level security; JWT-verified edge functions; least-privilege service roles.
    Identification & Auth (IA)Supabase Auth with email-based authentication; admin actions gated behind authenticated roles.
    System & Comms (SC)TLS 1.2+ enforced at Cloudflare edge; DDoS protection; data encrypted in transit.
    Audit & Accountability (AU)Moderation actions and org-level activity are logged; audit export available to pilot partners.
    Media Protection (MP)EXIF/GPS metadata stripped from uploaded photos on ingest; storage under RLS policies.

    Floodi is an early-stage MVP and is not currently FedRAMP-authorized. The underlying infrastructure providers (Supabase, Cloudflare) operate on SOC 2 Type II certified platforms. Floodi will pursue an appropriate authorization path if required by a specific award or contract.

    3. Hosting & data residency

    Application data is stored on Supabase (PostgreSQL + Storage); web delivery and edge functions run on Cloudflare. Data residency for a specific government engagement (including U.S.-only region pinning) can be confirmed and contractually scoped during pilot onboarding.

    4. Public records & FOIA posture

    Data Floodi provides to a government partner may become subject to Florida public-records law (Ch. 119, F.S.) or the federal Freedom of Information Act. Floodi only transmits public-safe fields (location, severity, age, verification context) and excludes private reporter contact details, user identifiers, and internal moderation notes from any government-facing feed, so partners can satisfy records requests without exposing personal data.

    5. Data ownership & deliverable rights

    Under a federal award or pilot agreement, data deliverables and their license terms (including any government-purpose rights) are defined in writing before work begins. Floodi retains ownership of its platform code and aggregated, anonymized intelligence unless a specific award dictates otherwise.

    6. Retention & disposal

    Resolved reports are retained up to 90 days in identifiable form, then anonymized. Government engagements may specify a different retention and secure-disposal schedule, which Floodi will honor for the contracted dataset.

    7. Service availability & business continuity

    Floodi's infrastructure is designed to remain operational during Florida hurricane season when demand is highest:

    LayerProvider & availability
    Web delivery & edge functionsCloudflare global edge network — 99.9% uptime SLA at CDN layer; DDoS-protected.
    Database & authSupabase (PostgreSQL) — automated daily backups; point-in-time recovery available.
    Data ingestion (NWS/USGS)Scheduled edge jobs with automatic retry logic; missed cycles self-correct on the next run.
    Photo storageSupabase Storage (S3-backed) — redundant object storage with RLS-gated access.

    For government pilot engagements, Floodi can provide a written uptime commitment, a formal incident response timeline (target: 4-hour acknowledgment / 24-hour resolution for P1 incidents), a named escalation contact, and a data export path so agencies are never locked in. These terms are negotiated and scoped in writing before a pilot begins.

    8. Contact

    Data governance, security questionnaires, and grant compliance documentation: [email protected]. See also the federal readiness page and security overview.

    Floodi is an independent, community-powered platform and is not affiliated with, endorsed by, or a replacement for the National Weather Service, NOAA, USGS, or FEMA. Floodi does not replace 911, official emergency alerts, evacuation orders, or instructions from local law enforcement and emergency management. In an emergency, always call 911.