SYSTEM // SECURITY POSTURE
Posture, attestations, operational reality.
STATUS OK · LIVE
We sell a security platform. That obligates us to a higher posture than most. Below is the honest, current state — including what's in progress and what's still on the roadmap.
ATTESTATION STATUS
SOC 2 TYPE II
IN PROGRESS
● AUDITOR ENGAGED
FedRAMP
MODERATE PATH
● PLANNED
CRYPTOGRAPHY
FIPS 140-3
● VALIDATED
DEPLOYMENT
GOV · GCC HIGH
● AVAILABLE
SECURITY PRACTICES
- P-01Least privilege by defaultCloud accounts onboarded with read-only scope; write scope per action class.
- P-02Tamper-evident audit logEvery platform action content-hashed; chain verifiable independent of PolicyCortex.
- P-03No PHI · No CUI · No PIIWe process configuration metadata only. Cloud APIs return resource state, not data.
- P-04SBOM + SAST + DASTContinuous supply chain scanning. Dependency vulnerabilities tracked + patched.
- P-05Pen-test annuallyIndependent third-party penetration testing on the production platform.
- P-06Incident response proceduresDocumented IR runbook · 24h notification SLA · customer-facing security report.
Have a security questionnaire (SIG-Lite, CAIQ, custom)? Email [email protected]. We respond within one business day.
