Skip to main content
State & Local

What a county or city should ask a data vendor

Every vendor can demo. Far fewer can tell you who owns the data, what the system looks like on the day the contract ends, who patches it at 2 a.m., and what it costs in year four. These are the ten questions, and the answers that should come back in writing.

The demo is the easiest part

A demo takes a skilled sales engineer about three weeks to build and about forty minutes to deliver. It runs on curated data, on a laptop the vendor controls, with the failure paths turned off. Nothing about a good demo predicts whether the system will still be running in year three, whether your records will be readable when the contract ends, or whether the annual invoice will double. Those outcomes are decided by contract language and engineering practice, and both are knowable before you sign. You just have to ask.

Local government buys differently from the federal government and carries a harder version of the same risk. A county has a smaller technical bench, a one-year budget cycle, an elected board that changes, and public-records obligations that attach to whatever the vendor stores. When a system fails in a federal agency, a program office absorbs it. When a system fails in a county, the treasurer, the sheriff, or the public works director absorbs it personally, in a public meeting.

Our team builds production data, analytics, and machine-learning systems for federal, state, and local customers, and we have sat on both sides of this table. What follows is the question set we would hand to a procurement officer who has to defend a selection later. Ten questions. Each one has a good answer and a telling answer.

Where local data projects actually go wrong: buyer risk weighting

Cost growth after year one
91%
No workable exit or data export
87%
Maintenance ends when the launch ends
82%
Ownership of derived data and models
78%
Integration breaks on upstream upgrades
71%
Records and audit obligations unmet
66%

Editorial weighting from public procurement records and practitioner reading; illustrative, not a measured statistic.

1. Who owns the data, and who owns what the system learns from it

Ownership of the raw records is usually the easy half. Most vendors will concede that your permit files, your dispatch logs, and your assessor rolls belong to you. The contested half is everything derived: the cleaned tables, the entity-resolution keys, the geocoded address points, the labeled training set, the tuned model weights, and the embeddings. A vendor can hand back your original CSVs and still keep the only artifact with real value.

Ask for three separate grants in writing. First, the agency owns the source data and all derived data, including cleaned, joined, enriched, and labeled forms. Second, the agency receives a perpetual, irrevocable, royalty-free license to any model trained on agency data, along with the training configuration needed to retrain it. Third, the vendor gets no right to use agency data to train products sold to other customers unless the agency grants that right separately and in exchange for something specific.

If federal grant dollars touch the purchase, the Uniform Guidance already sets a floor. Under 2 CFR 200.315, the federal awarding agency reserves a royalty-free, nonexclusive, irrevocable right to use work produced under the award. That clause does not protect the county by itself, but it does establish that data-rights language belongs in the contract, and it gives your attorney a familiar model. The federal analogue on the acquisition side is FAR 52.227-14, Rights in Data — General, which many state and local templates borrow from directly.

2. What does the day after the contract ends look like

Ask the vendor to describe termination day in operational detail. Not "we provide data export." What file formats, delivered how, on what schedule, with what documentation, and at what price. A ZIP of undocumented JSON is technically an export and practically a dead end. A usable exit package is open-format tabular data, a written schema dictionary, referential keys intact, attachments and scanned documents with their metadata, and a note explaining every code value.

Then ask for something stronger: a test restore. Once a year, the vendor delivers the full export, and your staff or a third party loads it somewhere else and confirms the record counts and a sample of rows. A vendor confident in the exit will agree to this and will schedule it. A vendor that has never done it will negotiate around it, and that reluctance is your answer.

Two more exit terms belong in the contract. A transition-services clause obligating the vendor to support migration for a defined window after termination at pre-agreed hourly rates, so the price is not set during a crisis. And a certificate of destruction confirming the vendor deleted agency data from production, backups, and any analytics copies, with a date by which backup expiry completes.

A ZIP of undocumented JSON is technically an export and practically a dead end. Ask for a test restore once a year, and watch how the vendor reacts.

3. What does "maintained" actually mean, in hours and names

"Fully supported" is marketing. Maintenance is a set of concrete commitments, and each one has a number attached. How fast are security patches applied after a vendor advisory, in days. What is the target uptime and what is the credit when it is missed. Who answers a ticket at 2 a.m. on a Sunday, and is that a person or a queue. How often do dependencies get upgraded, and who pays when a library version forces a rewrite.

Support and maintenance are different products. Support answers your questions. Maintenance keeps the system working as the world changes around it: the state changes a reporting format, the ERP vendor ships a major version, a certificate expires, a cloud service is deprecated with twelve months' notice. Systems rot without that work, and the rot is invisible for about eighteen months.

Ask who does it. Not the company name, the people. A serious answer names the engineers, describes their coverage, and explains the escalation path. Our own practice is to name the engineers assigned to a system in the proposal, keep the same people through delivery and sustainment, and bring in licensed professional engineers or domain specialists from our bench when the work touches structures, energy systems, clinical data, or transportation safety.

4. What does year two through year five cost

Ask for a five-year total, not a year-one price. Year one flatters every vendor because implementation is bundled and discounts are deepest. The costs that decide the real number are annual license escalation, seat growth, storage growth, integration maintenance, cloud consumption, retraining and model refresh, and the price of leaving.

Cost lineWhat the demo showsWhat to make them quote
Subscription escalationYear-one priceFixed annual cap in writing, commonly 3 to 5 percent, not "CPI or vendor list"
Seats and usersNamed users at go-livePrice at 2x users, and whether read-only viewers count
Data volumeCurrent record countStorage tier pricing and retention overage at year five volumes
Integrations"Connects to your ERP"Who pays to fix the connector when the ERP does a major upgrade
Model refreshAccuracy on the demo setRetraining cadence, who performs it, and the line-item cost
ExitNot mentionedExport fee, transition hourly rate, and escrow release cost

Two cost traps are specific to local government. The first is grant-funded implementation with general-fund sustainment: Treasury's State and Local Fiscal Recovery Funds carried an obligation deadline of December 31, 2024 and an expenditure deadline of December 31, 2026, and a large number of local data platforms were stood up on that money. When it is gone, the recurring cost lands on the operating budget, and somebody has to defend it. The second is egress. The major cloud providers moved to waive their own transfer fees for customers leaving, but the application vendor sitting on top of that cloud can still charge for extraction, and often does.

5. Where does the data physically live, and who can reach it

Ask for the hosting region, the subprocessor list, and the access model. Which cloud, which region, which availability zones, and does any component run outside the United States. Which subcontractors and third-party services touch the data, including analytics, error reporting, and support tooling. How many vendor employees can read production records, how that access is approved, and whether every read is logged in a way you can inspect.

The compliance overlay depends on the data. Criminal justice information pulls in the FBI CJIS Security Policy, which requires a signed CJIS Security Addendum for contractor personnel and fingerprint-based background checks. Health department and EMS data pulls in HIPAA and a business associate agreement under 45 CFR 164.504(e). School district data pulls in FERPA, where the school-official exception at 34 CFR 99.31 requires the district to keep direct control over the vendor's use of the records. Controlled unclassified information from a federal partner pulls in NIST SP 800-171.

For general-purpose systems, ask whether the vendor holds a SOC 2 Type II report or a StateRAMP authorization, now issued under the GovRAMP name. Insist on Type II specifically. A Type I report describes controls at a single point in time and can be earned in a week; Type II tests whether those controls operated over a period, usually six to twelve months. Ask for the report itself under NDA, and read the exceptions section, which is where the useful information lives.

6. What happens when the system is wrong

Any system that scores, ranks, flags, or predicts will be wrong sometimes, and in local government the wrong answer often lands on a resident. A benefits eligibility flag, a code enforcement priority, a risk score attached to a case, a tax valuation adjustment. Ask the vendor how a decision gets explained to the person affected, and how it gets reversed.

The practical requirements are unglamorous. Every automated output should carry the inputs that produced it, the model or rule version, and a timestamp, retained long enough to answer a challenge months later. Staff need an override that is logged with a reason. And someone has to review the override log, because a high override rate is the earliest available signal that the system is drifting away from reality.

Ask one more question here: what is the measured error rate, on which population, and how was it measured. A vendor that reports a single accuracy figure with no denominator and no breakdown by group has not done the work. A vendor that reports false-positive and false-negative rates separately, on a held-out sample from data resembling yours, has.

7. Who actually writes the code

The people in the room during procurement are frequently not the people who build the system. Ask directly: which named individuals will write this software, where are they, and what percentage of their time is committed. Then ask what happens if one of them leaves.

Ask about subcontracting depth too. A prime that subcontracts the build to a shop that subcontracts again has inserted two margins and two communication hops between your requirement and the keyboard. That structure is legal and sometimes reasonable, but you should know it exists before you sign, not when a defect takes six weeks to fix.

Our answer to this question is short because we keep the bench small and deep. A former professor in technology leads the engineering, ranked in the top 200 of more than 200,000 on Kaggle and holding seven cloud certifications, with twenty years of production systems built for federal agencies across five consulting firms, three of them federal. Named engineers, licensed professional engineers, and domain specialists across defense, health, energy, transportation, and public-sector data come in against the specific problem. The people named in the proposal are the people who show up.

8. Will you run it on our data, on our clock

The single most useful evaluation step costs almost nothing: ask each finalist to run the same task on a sample of your real data, in a fixed window, and report results on a scoring sheet you wrote. Use de-identified or public-record data if the sensitivity requires it. Two weeks is enough. Give every vendor the same extract, the same questions, and the same deadline.

A 30-day evaluation that fits a procurement calendar

1
Pull a representative data extract and write the scoring sheet before any vendor sees it
Days 1–5
2
Issue the same extract, the same task, and the same questions to every finalist
Day 6
3
Vendors work; written questions only, answers published to all bidders
Days 7–20
4
Results returned with method notes; staff reproduce two headline numbers
Days 21–25
5
Score against the sheet, then read the contract answers as a separate gate
Days 26–30

Score the method, not only the number. Ask how the sample was split, what was tuned, and whether anything was hand-corrected. A vendor that reports a slightly lower score with an honest method is the better partner than one that reports a perfect score it cannot reproduce.

9. What survives an audit

If any federal grant money funded the system, your records obligations follow the grant. Under 2 CFR 200.334, financial records, supporting documents, and statistical records must generally be retained for three years from the submission of the final expenditure report. Under 2 CFR 200.501, an entity expending $1,000,000 or more in federal awards in a fiscal year faces a single audit, a threshold that rose from $750,000 for fiscal years beginning on or after October 1, 2024. Procurement standards at 2 CFR 200.318 through 200.327 govern how you selected the vendor and require documented cost or price analysis.

Two more items catch local buyers. 2 CFR 200.216 prohibits using federal award funds to obtain covered telecommunications and video surveillance equipment or services, which reaches camera systems, sensor networks, and anything embedding them. And your state open-records law reaches data held by a vendor on your behalf; if a records request arrives, you need the ability to produce responsive material without the vendor's permission and without a bill attached. Put that in the contract as a records-cooperation clause.

10. What are you willing to put in the contract

Everything above is a conversation until it is a clause. The final question is the one that separates a supplier from a partner: which of these answers will you sign. A vendor that says yes in a meeting and no in redlines has told you what it is.

  • Data rights. Agency owns source and derived data; perpetual license to models trained on agency data; no cross-customer training without a separate grant.
  • Export. Open-format export with a schema dictionary, delivered on demand at no charge, plus an annual test restore.
  • Transition services. A defined post-termination support window at rates fixed today.
  • Source code escrow. Third-party agent, written release conditions, annual verified deposit.
  • Maintenance. Patch timelines in days, uptime target with credits, named escalation contacts.
  • Price protection. A capped annual escalation percentage across the full term, including renewal years.
  • Security. Hosting region, subprocessor list, breach notification hours, and the right to audit or to receive the SOC 2 Type II report.
  • Records. Cooperation with public-records and audit requests at no additional cost.

How to read the answers

A good vendor answers these in writing within a few days, because the answers already exist. The information lives in a runbook, a security package, and a standard contract exhibit. A vendor that needs three weeks and a legal review to tell you who owns your data is telling you the position has never been settled.

Watch for three specific tells. Ownership language that grants the agency a "license to use" its own records rather than ownership. Maintenance described only in adjectives, with no days, no hours, and no names. And a five-year cost that arrives as a single number with no line items, which almost always means the escalation is where the margin is.

None of this requires an in-house data team to evaluate. It requires a written question set, the same set sent to every bidder, and the discipline to treat the contract answers as a scored gate rather than paperwork after selection.

What we put in writing before you buy

We answer all ten of these before a purchase order exists, in a document you can attach to a board packet. The agency owns the source data, the derived data, and holds a perpetual license to any model trained on it. The export is open-format with a schema dictionary and we will run a test restore with your staff every year. Maintenance comes with named engineers, patch windows in days, and an escalation path with phone numbers. The cost table runs five years with escalation capped in the contract. And the exit is priced on the day you sign, not on the day you leave.

We build these systems for federal, state, and local customers as prime or as a subcontractor, and we are equally willing to review a proposal you received from someone else. A second technical read on a vendor's answer sheet is cheap, fast, and frequently the highest-value hour in a procurement.

Frequently asked questions

Who owns data a vendor cleans, joins, or labels for a local government?

Whoever the contract says. Absent explicit language, vendors routinely claim derived data, labeled training sets, and model weights as their own work product. Write ownership of source and derived data to the agency, and add a perpetual, royalty-free license to any model trained on agency records along with the configuration needed to retrain it.

What should a data export at contract end include?

Open-format tabular data with referential keys intact, a written schema dictionary, code-value definitions, and all attachments with their metadata. Add an annual test restore so the export is proven to load somewhere else before you need it, and a transition-services clause that fixes post-termination hourly rates in advance.

How do you estimate the true cost of a government data platform?

Build a five-year table, not a year-one price. The lines that move it are annual escalation, user growth, storage growth, integration maintenance when upstream systems upgrade, model retraining, and extraction cost at exit. Cap the escalation percentage in the contract across renewal years.

Does SOC 2 or StateRAMP matter for a county purchase?

It helps, with a caveat. Require SOC 2 Type II rather than Type I, since Type II tests whether controls operated over a period instead of describing them at one moment. StateRAMP, now issued as GovRAMP, is useful for cloud offerings. Neither replaces the specific overlays: CJIS for criminal justice data, HIPAA for health data, FERPA for student records, NIST SP 800-171 for controlled unclassified information.

What record-keeping rules apply when federal grant money funds the system?

The Uniform Guidance applies. Records are generally retained three years from the final expenditure report under 2 CFR 200.334, procurement is governed by 2 CFR 200.318 through 200.327, and entities expending $1,000,000 or more in federal awards in a fiscal year face a single audit under 2 CFR 200.501.

1 business day response

Send us the scope, or the proposal you are holding

Email the draft scope, the RFP, or a vendor's proposal to [email protected]. Within one business day you get written answers to all ten questions applied to that specific scope: a data-ownership line, an exit plan, a maintenance description with named engineers, and a five-year cost table. If we are not the right builder for it, we say so in the same reply and tell you what to ask instead.

Send the scopeCapabilitiesMore insights →
UEI Y2JVCZXT9HP5CAGE 1AYQ0NAICS 541512SAM.GOV ACTIVE