Skip to main content
Skip to main content
Trust CenterSecurity & compliance · verifiable, not vague

Security and compliance you can verify.

VETR is built for government contracting, where trust is the product. Here's exactly where our security and compliance posture stands today — stated honestly, including what's still in progress.

Frameworks

Compliance frameworks — current status.

We never claim a certification we don't hold. Where a framework is still in preparation, we say so — plainly.

SOC 2 Type IIIn preparation

A SOC 2 Type II audit covering Security, Availability, and Confidentiality is in preparation — controls are mapped to the Trust Services Criteria, but an independent CPA firm has not yet been engaged and the observation window has not started. Report shared with Enterprise customers under NDA on completion.

NIST SP 800-171Controls mapped

Controls mapped to NIST SP 800-171 for protecting Controlled Unclassified Information (CUI), including automatic redaction of sensitive identifiers before any third-party AI call, per-tenant access enforcement, and continuous-monitoring alerting. Formal assessment not yet undertaken.

FedRAMP 20xIn preparation — not yet authorized

We are pursuing FedRAMP 20x (Low first). VETR runs in AWS GovCloud (us-gov-west-1) with all 46 Key Security Indicators mapped, an OSCAL System Security Plan, and continuous monitoring live — and we are preparing to engage an accredited 3PAO for the independent assessment. VETR is not yet FedRAMP-authorized.

CMMC Level 2Aligned

Security controls aligned with CMMC Level 2 practices, which build on NIST SP 800-171, for organizations handling CUI in the defense industrial base. Alignment is self-attested and mapped control by control; VETR does not hold a CMMC certification and does not claim one.

Section 508WCAG 2.1 AA — automated checks clean

WCAG 2.1 Level AA: automated checks (axe-core runtime + ESLint jsx-a11y) report 0 violations across public and authenticated pages. Automated tooling catches only part of WCAG — no independent manual or assistive-technology audit has been performed yet. A VPAT/ACR is maintained and available on request.

Section 889Program in place

We maintain a review process for covered-telecommunications restrictions and supply-chain representations relevant to the platform environment. Detailed representations available on request.

VETR currently holds no third-party certifications or authorizations. The statuses above reflect our self-assessed posture and work in progress, stated conservatively — we update them here as independent assessments complete.

Controls

How we protect your data.

Encryption

  • TLS 1.3 in transit with a TLS 1.2 floor (HTTPS-only, HSTS)
  • AES-256 at rest across database, object storage, and cache; sensitive PII additionally encrypted at the app layer
  • Secrets in AWS SSM Parameter Store

Access control

  • TOTP two-factor authentication
  • Role-based access (org owner / manager / contributor)
  • Enforced enrolment for privileged accounts

Tenant isolation

  • Automatic per-organization data scoping
  • Cross-tenant access blocked at the query layer
  • Verified by a cross-tenant isolation test suite

Auditability

  • Append-only audit log of privileged actions
  • Impersonation re-validated every request + logged
  • WORM / object-lock archival on the roadmap

Application security

  • Upload content-sniffing + AV hook
  • SSRF guard (blocks IMDS / DNS-rebinding)
  • Pervasive rate limiting + signed webhooks

Resilience

  • Automated RDS backups + point-in-time recovery
  • Deploy circuit-breaker with auto-rollback
  • Fail-closed migrations (no half-migrated boot)

Data handling & residency

  • Customer data is hosted in AWS GovCloud (us-gov-west-1), the isolated US-government cloud region, with CUI workloads inside the GovCloud boundary.
  • Each organization's data is isolated; one tenant can never query another's.
  • You can request export or deletion of your organization's data (GDPR/CCPA rights honored — see the Privacy Policy).
  • AI requests send only the context needed for that task; your data is never used to train shared models.

Subprocessors

  • Amazon Web Services (AWS GovCloud)Cloud hosting, database, storage (us-gov-west-1)
  • StripeSubscription billing + payments (PCI-DSS Level 1)
  • Amazon Bedrock (AWS GovCloud)AI generation (RFP parsing, drafting, assistant) inside the GovCloud boundary — no external-LLM egress
  • Amazon SES / WorkMailTransactional + branded email

Running a vendor security review?

Tell us what your security or contracting team needs — our NIST 800-171 mapping, the SOC 2 report when it lands, a completed security questionnaire (SIG/CAIQ), or a DPA — and we'll get it to you.