All good questions that I believe we can answer in time. Maybe not fully before the meeting this evening but please know that Juan Olmeda, our IT Director, and I will be on hand tonight to help answer what we can.
Thx.
Sent from my iPhone
I am sharing the emails that I send to Bend City Council in hopes that it will one day be beneficial to others who wish to get involved in local governance.
All good questions that I believe we can answer in time. Maybe not fully before the meeting this evening but please know that Juan Olmeda, our IT Director, and I will be on hand tonight to help answer what we can.
Thx.
Sent from my iPhone
Hi Mike,
Thank you again for the thorough response. I appreciate you coordinating with IT and Engineering staff, and I also appreciate that you and staff will be available tonight if Council has additional questions.
Your response answered many of the questions I raised and was helpful in understanding how the City is approaching these systems. Given that Council may act on these items tonight, I would appreciate any additional responses staff can provide before or during the meeting. If some of these questions require more time, it would still be helpful for Council and the public to know which items remain under review.
On the Aclara item, you noted that Aclara retains approximately three years of meter-reading history in the cloud, while the City’s on-premises database currently retains that data indefinitely. Is there a formal retention policy for the City-held meter data, and what is the operational reason for indefinite retention?
You also noted that access is role-based and activity is logged. Is there a periodic audit process for those logs? If so, how often are they reviewed, and by whom?
You mentioned that meter data may be released through the public records request process. Given that hourly, address-specific water-use data can potentially reveal household routines, occupancy patterns, vacations, caregiving patterns, or other sensitive details, has the City considered whether any Oregon public-records exemptions, redaction practices, or special review procedures should apply before releasing that kind of granular utility data?
I also noticed that WaterSmart/WaterWise does not appear to be discussed in the public agenda packet. Since staff’s response indicates that meter data is integrated with that platform, could the City clarify what data is shared with it and what privacy, retention, vendor-use, and security terms govern that relationship?
Finally, does the Aclara agreement itself limit Aclara’s use of City or customer data, separate from the City’s own stated limits on use of the data?
On the ProjectTeam item, your response identifies several important controls, including MFA, role-based access controls, encryption, logging, security assessments, AWS hosting, and cyber-liability insurance.
For my understanding, has the City directly reviewed the underlying SOC 2, FedRAMP, GovRAMP, or comparable documentation as part of its security review, or is the City relying on vendor representations for some of those controls? Also, has the City reviewed a full list of subprocessors beyond AWS, and what is the contractual breach-notification timeline?
I do not raise these questions as criticism of staff or of either procurement. My larger concern is that privacy and cybersecurity issues now appear in many routine systems, including utilities, cloud platforms, GIS tools, permitting systems, transit technology, and contractor portals.
This exchange has been helpful because it shows how much important information may not be visible in the public packet alone. My hope is that Bend can eventually build a standard privacy and cybersecurity checklist into technology procurements and renewals, so these questions are considered consistently and early.
Thank you again for taking the time to engage on this. I appreciate it.
Best,
Jonathan Westmoreland
Bend Privacy Alliance
Hi Jonathan – Thank you for reaching out. I have connected with fellow IT and Engineering staff and have two follow up responses below for you below. I am hoping that these address the primary concerns outlined in your earlier email. Staff and I will plan to be at City Council meeting tonight (starts at 6pm) to help answer any additional questions regarding items 4D and 4F.
Item 4F – Aclara
The City’s Advanced Metering Infrastructure (AMI) system uses Aclara to collect water meter readings, including the account number, meter read, and the date and time of the reading. Customer information is uploaded daily from the City’s financial system into Aclara to support Utility Billing research and customer service activities. Regarding data retention, Aclara retains approximately three years of meter-reading history in its cloud environment, while the City’s on-premises database currently retains the data indefinitely. Access to individual household water-use histories is restricted to staff who have been provided an Aclara account based on specific job responsibilities.
Data transmissions are encrypted, and data stored within Aclara’s cloud environment and the City’s SQL databases are also encrypted. Access is restricted based on role and activity is logged. Data may be released through the public records request process, and the City’s use of meter data is limited to billing, system maintenance, leak detection, customer-requested services, and integration with WaterSmart, a customer-facing water conservation and leak-detection platform. Aclara personnel has remote access to customer data when performing maintenance or supporting system infrastructure, such as work related to the data collection units (DCUs) that receive meter transmissions.
Item 4D -ProjectTeam Cloud Platform
IT and Information Security reviewed the vendor’s controls and confirmed that several key security requirements have been met. The vendor verified that multifactor authentication (MFA) will be required for all City employees, contractors, and vendor accounts. The application further provides Role-Based Access Controls (RBAC) for granular user authentication and enforcement of least-privilege access. In addition, the vendor confirmed that all City data and backups are encrypted both in transit and at rest, helping protect sensitive information throughout its lifecycle. The review also found that the vendor has undergone recognized security assessments and maintains GovRAMP and FedRAMP compliance (please see below for more information), while its hosting provider, AWS, maintains SOC 2 Type II and SOC 3 compliance.
The review further confirmed that least-privilege access controls are enforced for all internal and external users and that user activity, including access events, is logged. The vendor identified AWS as the hosting provider responsible for storing and maintaining City data, satisfying the requirement to disclose and review entities that may possess City information. The vendor confirmed that they maintain appropriate cyber-liability insurance.
FedRAMP (Federal Risk and Authorization Management Program) is the U.S. federal government’s standardized framework for assessing, authorizing, and continuously monitoring the security of cloud services used by federal agencies.
The vendor’s compliance with both FedRAMP and GovRAMP indicates that it has undergone rigorous third-party security reviews and maintains cybersecurity controls that align with government-sector standards.
Reach out if we need to connect this afternoon. Otherwise, I am happy to connect before or during tonight’s meeting.
Thank you!
Mike Buettner
PUBLIC WORKS DIRECTOR
Public Works
Mayor Kebler,
Thank you, I appreciate the quick response.
I understand that any Councilor may choose to pull an item from the consent agenda during the meeting. I would also appreciate staff responses when they are available.
Because these items are scheduled for possible approval tomorrow night, I hope at least the key privacy and cybersecurity questions can be addressed before or during the meeting, so Council and the public have that information before action is taken.
Thank you again.
Jonathan Westmoreland
Bend Privacy Alliance
Thanks for your questions. If a Councilor wishes to pull an item from the consent agenda item tomorrow night, they can certainly do so. I will also ask staff respond when they are able to your questions via email so you have the information.
Thanks,
Melanie
Mayor Kebler and Members of the Bend City Council,
On behalf of Bend Privacy Alliance, I am writing to request that consent-agenda items 4D and 4F on the July 15, 2026 agenda be pulled for brief public discussion.
We are not asking the Council to reject either item. We are asking for basic public clarification about the security and privacy protections associated with two systems that will hold or generate potentially sensitive information.
Item 4F concerns the purchase of Aclara water-meter transmission units. The supporting materials indicate that these devices can generate hourly, time-stamped household water-use readings and support on-demand readings. Data at that level of detail can reveal occupancy and household activity patterns.
Before authorizing a five-year purchase, we ask the City to publicly explain:
Item 4D concerns the ProjectTeam cloud platform for capital-project documents, workflows, financial records, contractor collaboration, and integrations with other City systems.
The proposed data-protection addendum contains several encouraging provisions, including City ownership of its data, restrictions on sale and unrelated data mining, domestic data-storage requirements, incident-reporting obligations, and post-contract data destruction.
However, the public packet does not clearly state whether:
These may already be addressed through the City’s internal security-review process. A brief explanation during the meeting would give the public confidence that the privacy and cybersecurity implications were considered before approval.
As more public services rely on connected devices and cloud platforms, procurement is one of the most important points at which the City can establish meaningful safeguards. Addressing these questions before approval is easier and less costly than trying to add protections after deployment.
Thank you for your consideration and for making these issues part of the public record.
Sincerely,
Jonathan Westmoreland
Bend Privacy Alliance
Protecting privacy, transparency, and civil rights in Bend
Hello Jonathan,
Confirming receipt of your email, 6/3/2026.
Ashley Bontje
CITY RECORDER
City Manager’s Office
To: Bend City Council (councilall@bendoregon.gov)
Cc: Ashley Bontje, City Recorder (abontje@bendoregon.gov); City Manager’s Office (communications@bendoregon.gov)
Subject: Petition for Council Review of Police Department Policy 428 — Bend Code 1.30.005(C)
To the City Council, Ms. Bontje, and the City Manager’s Office,
Attached is a petition, submitted under Bend Code 1.30.005(C), requesting that the City Council review Bend Police Department Policy 428 (Automated License Plate Readers) at a public meeting with opportunity for public comment.
Bend Code 1.30.005(C) provides that “the Council may review any regulation adopted by the City Manager on its own motion, or on petition of any person filed within 30 calendar days of the first public posting of the regulation.” This petition is filed within that window. Under BC 1.05.020, the 30-day period runs through Monday, June 15, 2026, whether Policy 428 was first posted on May 14 or May 15, 2026. The petition explains the basis for those dates.
Because 1.30.005(C) does not specify a filing location, I am submitting this petition by email to the City Council, the City Recorder, and the City Manager’s Office to ensure proper receipt. A hard copy is also being delivered to City Hall / mailed to the City Recorder. If the City believes this petition should be filed in a different manner or location, I respectfully request written notice so I can promptly correct it within the time allowed.
I would appreciate written acknowledgment of receipt, including the date of filing.
Thank you for your consideration.
Sincerely,
Jonathan Westmoreland
Resident, City of Bend, Oregon
Attachment: Petition for City Council Review of Bend Police Department Policy 428 (BC 1.30.005(C))
Hi Melanie,
Thank you for the thoughtful reply, and for offering to talk individually. I understand the public-meeting-law concern and appreciate you moving Council to BCC.
I agree on the core points: Council does not directly manage the Police Chief or department staff, police policies are generally administrative documents, and state law applies whether or not Policy 428 restates it.
The distinction I am trying to draw turns on a word in your own reply. You wrote that Council does not “typically” review administrative police policies. I agree — and that is the distinction. Policy 428 is not a typical administrative policy. Most department policies govern internal officer conduct. Policy 428 governs a public-facing surveillance system: the collection, retention, sharing, auditing, and oversight of automated license plate reader data associated with members of the public, most of whom are not suspected of anything. A policy that determines how the City collects, stores, shares, and may search time-and-location data associated with ordinary residents’ vehicles feels like a matter of public governance and civil liberties, not only day-to-day administration.
In looking at how the Charter and Code address this kind of question, a few provisions seemed relevant and I wanted to flag them for the conversation. Charter Section 6 vests all powers of the City in the Council except as the Charter provides otherwise, and Section 5 directs that the Charter be liberally construed so the City may exercise its powers fully. Bend Code 1.30.005(E) requires the City Manager’s regulations, policies, and guidelines to be consistent with the Charter, the Bend Code, and Council ordinances, and 1.30.005(C) provides a mechanism for Council review of a City Manager regulation, either on its own motion or on petition of any person within 30 days of first public posting. I’m not assuming Policy 428 falls within (C) — the Code doesn’t define “regulation,” and I’d genuinely value the City’s view on that. But it does seem like the kind of question worth understanding the answer to, given the public-facing nature of what 428 governs.
A couple of things I’d appreciate your thoughts on whenever we talk: how the City thinks about whether a public-facing surveillance policy like 428 falls within 1.30.005(C), and whether there’s a sense of when Council might see the Policy 428 framework — and any related safeguards — in a public setting. I appreciate your clarification that any new fixed-ALPR use will require a contract that comes before Council with public comment, and that’s helpful. My remaining concern is sequencing: by the time a contract reaches Council, the governing framework may already be largely set by the department policy and the vendor’s terms. Seeing the policy framework publicly before or alongside any such contract would let the community weigh in while the rules can still be shaped.
That same reasoning is why I raised the surveillance-technology procurement and oversight ordinance in my original letter. Adopting an ordinance is legislation, squarely Council’s role, and it would set clear public rules up front rather than handling each issue ad hoc after it becomes a controversy. I’d love to discuss that on the call as well, if you have time.
My schedule is pretty flexible for the next week or so — if you can send a couple of times that work for you, I can accommodate. Thank you again for engaging with this so seriously.
Best,
Jonathan Westmoreland
Hi Jonathan,
The City Council does not typically review administrative polices of the police department, as we are not direct managers of the police department nor any other staff other than the City Manager. This is why I forwarded your feedback to the Chief. Also, it’s not possible to really engage in discussion and deliberation with you over email with all of us included as that would violate public meeting laws. I’m happy to give you a call to discuss more individually. I am moving Council to BCC to avoid further group emails at this point.
Some other clarifications:
Any new use of fixed ALPR will require a contract, that contract will come before Council at a public meeting at which public comment will be available, and discussion can be had at that time of whether Councilors want to support such a contract or not. Written comments from the public on items of general interest are received directly to us via email to Councilall@bendoregon.gov – unless it is a land use public hearing our staff typically do not compile comments for the agenda packet but we see them in our email.
On policy 428 – as is the case with many administrative or city policies that are governed by state law, it is not necessary to copy the exact, full language of the statute into our policy. The state law will always apply, even if our policy does not incorporate each and every word. Admin policies guide our departments and are operational documents – they do not replace or override state laws and statutes, which always apply.
Please let me know if you’d like to chat further and I can give you a call.
Thanks,
Melanie