Security
We build compliance tools. Security is in our DNA. Here's how we protect your data.
Encryption
Application providers encrypt stored data and data in transit. Evidence-file access uses time-limited signed URLs.
Infrastructure
Hosted with established cloud providers; provider assurance reports are separate from CMMC Command's own security status.
Authentication
Enterprise-grade identity provider with Google OAuth, MFA support, and session management. Role-based access control across 5 roles (admin, assessor, employee, auditor, external assessor).
Privacy by Design
Analytics autocapture is disabled. Analytics and error monitoring are configured to mask inputs and omit page URLs. Do not submit CUI or classified information.
Security Architecture
- All database mutations require authenticated JWT from our identity provider
- Subscription changes only via verified payment processor webhook signatures
- Audit logging as internal mutations. No client-callable audit writes
- File upload pre-validation (type, size) before URL generation
- Rate limiting at the edge proxy layer (100 req/IP/60s)
- Security headers: HSTS, X-Frame-Options, X-Content-Type-Options, Referrer-Policy, Permissions-Policy
CUI Data Handling
CMMC Command is a preparation and workflow platform, not a CUI enclave. The platform is not intended or authorized for CUI or classified information. Do not upload either. User-uploaded evidence files are stored, and limited marker screening does not determine whether a file contains CUI.
- AI routes are designed to send selected assessment metadata and limited company profile data, not uploaded documents
- Limited marker checks can reject some AI inputs; they do not detect every form of CUI or determine information status
- Evidence-file screening is best-effort; unsupported formats and images require manual review
- Integration syncs are designed to collect selected security-tool metadata rather than documents; connected-system owners must still prevent CUI from entering the platform
- Error monitoring is configured to mask inputs and omit page URLs
- Product analytics runs with autocapture disabled and input masking enabled
Compliance Roadmap
- Infrastructure providers publish their own independent security and compliance reports
- SOC 2 Type II certification for CMMC Command is on our 2027 roadmap
- Penetration testing planned as part of annual security review cycle
Responsible Disclosure
If you discover a security vulnerability, please report it to security@cmmccommand.org. We will review the report and respond with next steps as practicable.