Seven federal systems, and what the record shows for each.
These are the systems where the Studio's work touches something a person actually uses to vote, travel, sign in, or get medicine. For each one we list what is on the record, what the responsible agency says, and where our own confidence runs out.
The Executive Office of the President holds the domain registration, and the agency that runs the service does not.
The system gathers data from the public, and we found no privacy filing for it.
Documented but not yet consequential, or awaiting a record we don't have.
Vote.gov preview
A working preview of vote.gov was built inside the Studio's staging environment, registered to the Executive Office of the President. The live vote.gov belongs to the Election Assistance Commission, which Congress made an independent bipartisan body after the 2000 Florida recount for exactly this reason: a sitting president is not supposed to control the place where citizens register to vote.
The certificate was logged April 10, 2026 ten days after Executive Order 14399 set a June 29 deadline for DHS to stand up citizenship-list infrastructure. A voter-facing federal site existed on White House infrastructure while the statutory owner of vote.gov was, on its own account, still only in discussions about modernization.
- Registered to: Executive Office of the President
- Statutory owner of vote.gov: Election Assistance Commission
- Certificate logged: April 10, 2026
- Behind the “loveisaskill” Cloudflare gate
Confirms it held discussions with the Studio about modernizing vote.gov and says the project has since been paused. The commission states the live vote.gov remains under its own control and is not connected to White House systems.
Passports.gov
Passports are issued by the State Department. The registry puts this domain under the White House instead. What loads today is a sign-in wall: enter an email, receive a six-digit code. There is no State Department seal, no agency name, and no privacy notice. The security contact field in the .gov registry is blank.
Two photo upload subdomains appeared within a single hour on May 26, 2026. A passport photo is biometric data. Collecting it through a White House-controlled domain, with no published privacy filing and no named security contact, is the specific thing we think warrants an answer.
- First certificate: May 5, 2026
- Photo upload subdomains: May 26, 2026, within one hour
- Registered to: Executive Office of the President
- Security contact field: blank
Says it continues to work closely with the White House to improve passport services while maintaining the security of passport programs and related technology.
Login.gov
The federal government's shared sign-in service. More than 150 million people have accounts, and it performs biometric identity verification. Greg Hogan, formerly Chief Information Officer at OPM, now runs it. When a federal court enjoined DOGE personnel from OPM personnel records, three people were granted exceptions and Hogan was one of them.
We are marking this Watch rather than something stronger because we have not documented any change to how Login.gov handles data. The concern here is about who holds the access, not about a change we can point to.
- 150M+ accounts · biometric verification
- Greg Hogan, former OPM CIO, now leads Login.gov work
- One of three exceptions to the OPM records injunction (AFSCME v. SSA)
- No documented change to data handling
TrumpRx.gov
A federal drug pricing site documented running PostHog session recording. Session recording captures far more than page views: mouse movement, clicks, scrolling, and form interaction, reconstructed as a replayable session. IP addresses were not stripped. The deployment used a reverse-proxy configuration routing analytics through a first-party path, which has the effect of bypassing ad and tracker blockers.
The tracking was apparently removed in June 2026, after the Guardian sent the White House detailed questions about the Studio's operations on June 4. Checking the site today may show nothing. The finding is what was documented before that date, and the removal itself.
We found no System of Records Notice in the Federal Register and no published Privacy Impact Assessment for this system. Whether either was legally required depends on an unresolved question we set out on the Evidence page. What is not in dispute is that neither exists.
- PostHog session recording documented (removed ~June 2026)
- IP addresses not stripped
- Reverse-proxy routing defeats tracker blocking
- No SORN found in Federal Register search
- No published Privacy Impact Assessment found
DHS SAVE and SSA records
Executive Order 14399 directs DHS and SSA to compile Confirmed Citizen Lists, with a June 29, 2026 infrastructure deadline. SAVE was designed to let agencies check immigration status for benefits eligibility; repurposing it as a voter-roll filter is a different use of the same data. The accuracy concern was borne out of the expanded system screened more than 67 million registered voters and flagged thousands as potential noncitizens, many of whom turned out to be citizens eligible to vote.
- EO 14399 § 4(c): DHS infrastructure deadline of June 29, 2026
- DHS Secretary approved the USCIS build plan on June 8, 2026
- Held unlawful June 22, 2026: Privacy Act, Social Security Act, and APA violations
- Screened 67M+ registered voters before being enjoined
- DOJ told a court the named agencies had not begun preparations
- No documented Studio role in building this system
The unannounced staging environments
Certificate logs show roughly 40 Studio subdomains that were never announced, including staging previews for State Department, NASA, and DHS properties. All trace back to the Executive Office of the President and sit behind the same private Cloudflare account.
One deserves separate attention: fbi-kirk-tipline.previews.ndstudio.gov. A tipline is a system that collects reports from members of the public about other people. If the White House design office is building a tipline environment carrying the FBI's name, the questions are who requested it, what it collects, who receives the submissions, and whether the FBI knows.
- ~40 unannounced subdomains found via certificate transparency logs
- Staging previews referencing State, NASA, and DHS properties
- fbi-kirk-tipline.previews.ndstudio.gov - purpose unknown
- All registered to the Executive Office of the President
- All behind a single private Cloudflare account
The AutoMonitor script
A custom JavaScript file of roughly 540 lines, served from Studio infrastructure and deployed across Studio-run federal sites. It generates persistent session identifiers and posts telemetry to a Studio-controlled analytics endpoint. Unlike PostHog, this is not a commercial product with published documentation. It was written for these sites, and nothing describes what it collects or where the data goes.
This is the piece of the story a reader can least easily check for themselves, and the piece we would most like technical information about. The script is publicly served, so anyone with a browser can read it.
- ~540 lines of custom JavaScript
- Generates session IDs; posts to analytics.infra.ndstudio.gov
- Deployed across multiple Studio-run federal sites
- No published documentation of purpose or retention
The sites don't meet the accessibility standard federal law requires
Everything above concerns how these systems are governed. This concerns whether they work. Under Section 508 of the Rehabilitation Act, federal electronic content must be accessible to people with disabilities, measured against the Web Content Accessibility Guidelines. Reviewers keep finding that Studio sites don't meet it.
An official told Nextgov/FCW that the team adheres to standard accessibility processes and that "when things aren't working, they fix them very quickly," and described the Studio's work as outstanding modernization of federal digital services.
Read that answer closely. It concedes that things aren't working and describes a practice of fixing them after launch. A live federal site announcing its own pending Section 508 review says the same thing more plainly: the review came after the launch, not before. That is the identical sequence this site documents on privacy: build first, comply when someone notices.
A former GSA Technology Transformation Services employee told NOTUS that in theory an inspector general could investigate whether federally created sites meet the required standards, but that in practice most enforcement is self-imposed: there is no accessibility police. An office outside inspector general jurisdiction is therefore outside the only mechanism that would catch this.
The strongest argument against us here.
Roughly half of federal websites were already inaccessible before the Studio existed, along with being slow and hard to use on phones. Fixing that is a real problem worth an office, and it is the most defensible thing about the Studio's mission. The objection we would make is narrower: the administration eliminated 18F — the office that did this work inside GSA's accessibility and privacy review process — and replaced it with one that ships first and reviews after.
You can check this yourself.
The free automated tools are axe DevTools, WAVE, or Lighthouse in Chrome. These will audit any page against WCAG in seconds. Run one on trumprx.gov or realfood.gov.
Two things you might expect here
The company holds large DHS and ICE data-integration contracts and is frequently named in coverage adjacent to this story. We have found no evidence connecting Palantir to any Studio system. Listing a company in order to say we found nothing still puts its name on a page about federal misconduct, and readers reasonably infer we would not have listed it without a reason. If a contract, a subprocessor disclosure, or a shared endpoint turns up, it goes here with the document attached.
Real, litigated, and consequential; but we have found nothing tying it to the Studio, and this page is about Studio infrastructure. Tracking every election-adjacent policy fight dilutes the thing we can actually document. It remains an open question rather than a system.
On the certificate count. A figure of 979 certificates for ndstudio.gov circulates in coverage of this story. That number counts every certificate ever issued, including automatic renewals, which for a normally operated site can run into the hundreds in a year. It is not evidence of anything. The meaningful figure is the number of distinct unannounced hostnames, which is roughly 40.