Skip to main content
Back to Home

Security

We build compliance tools. Security is in our DNA. Here's how we protect your data.

Encryption

Application providers encrypt stored data and data in transit. Evidence-file access uses time-limited signed URLs.

Infrastructure

Hosted with established cloud providers; provider assurance reports are separate from CMMC Command's own security status.

Authentication

Enterprise-grade identity provider with Google OAuth, MFA support, and session management. Role-based access control across 5 roles (admin, assessor, employee, auditor, external assessor).

Privacy by Design

Analytics autocapture is disabled. Analytics and error monitoring are configured to mask inputs and omit page URLs. Do not submit CUI or classified information.

Security Architecture

  • All database mutations require authenticated JWT from our identity provider
  • Subscription changes only via verified payment processor webhook signatures
  • Audit logging as internal mutations. No client-callable audit writes
  • File upload pre-validation (type, size) before URL generation
  • Rate limiting at the edge proxy layer (100 req/IP/60s)
  • Security headers: HSTS, X-Frame-Options, X-Content-Type-Options, Referrer-Policy, Permissions-Policy

CUI Data Handling

CMMC Command is a preparation and workflow platform, not a CUI enclave. The platform is not intended or authorized for CUI or classified information. Do not upload either. User-uploaded evidence files are stored, and limited marker screening does not determine whether a file contains CUI.

  • AI routes are designed to send selected assessment metadata and limited company profile data, not uploaded documents
  • Limited marker checks can reject some AI inputs; they do not detect every form of CUI or determine information status
  • Evidence-file screening is best-effort; unsupported formats and images require manual review
  • Integration syncs are designed to collect selected security-tool metadata rather than documents; connected-system owners must still prevent CUI from entering the platform
  • Error monitoring is configured to mask inputs and omit page URLs
  • Product analytics runs with autocapture disabled and input masking enabled

Compliance Roadmap

  • Infrastructure providers publish their own independent security and compliance reports
  • SOC 2 Type II certification for CMMC Command is on our 2027 roadmap
  • Penetration testing planned as part of annual security review cycle

Responsible Disclosure

If you discover a security vulnerability, please report it to security@cmmccommand.org. We will review the report and respond with next steps as practicable.