Security and compliance you can verify.
VETR is built for government contracting, where trust is the product. Here's exactly where our security and compliance posture stands today — stated honestly, including what's still in progress.
Compliance frameworks — current status.
We never claim a certification we don't hold. Where a framework is still in preparation, we say so — plainly.
A SOC 2 Type II audit covering Security, Availability, and Confidentiality is in preparation — controls are mapped to the Trust Services Criteria, but an independent CPA firm has not yet been engaged and the observation window has not started. Report shared with Enterprise customers under NDA on completion.
Controls mapped to NIST SP 800-171 for protecting Controlled Unclassified Information (CUI), including automatic redaction of sensitive identifiers before any third-party AI call, per-tenant access enforcement, and continuous-monitoring alerting. Formal assessment not yet undertaken.
We are pursuing FedRAMP 20x (Low first). VETR runs in AWS GovCloud (us-gov-west-1) with all 46 Key Security Indicators mapped, an OSCAL System Security Plan, and continuous monitoring live — and we are preparing to engage an accredited 3PAO for the independent assessment. VETR is not yet FedRAMP-authorized.
Security controls aligned with CMMC Level 2 practices, which build on NIST SP 800-171, for organizations handling CUI in the defense industrial base. Alignment is self-attested and mapped control by control; VETR does not hold a CMMC certification and does not claim one.
WCAG 2.1 Level AA: automated checks (axe-core runtime + ESLint jsx-a11y) report 0 violations across public and authenticated pages. Automated tooling catches only part of WCAG — no independent manual or assistive-technology audit has been performed yet. A VPAT/ACR is maintained and available on request.
We maintain a review process for covered-telecommunications restrictions and supply-chain representations relevant to the platform environment. Detailed representations available on request.
VETR currently holds no third-party certifications or authorizations. The statuses above reflect our self-assessed posture and work in progress, stated conservatively — we update them here as independent assessments complete.
How we protect your data.
Encryption
- →TLS 1.3 in transit with a TLS 1.2 floor (HTTPS-only, HSTS)
- →AES-256 at rest across database, object storage, and cache; sensitive PII additionally encrypted at the app layer
- →Secrets in AWS SSM Parameter Store
Access control
- →TOTP two-factor authentication
- →Role-based access (org owner / manager / contributor)
- →Enforced enrolment for privileged accounts
Tenant isolation
- →Automatic per-organization data scoping
- →Cross-tenant access blocked at the query layer
- →Verified by a cross-tenant isolation test suite
Auditability
- →Append-only audit log of privileged actions
- →Impersonation re-validated every request + logged
- →WORM / object-lock archival on the roadmap
Application security
- →Upload content-sniffing + AV hook
- →SSRF guard (blocks IMDS / DNS-rebinding)
- →Pervasive rate limiting + signed webhooks
Resilience
- →Automated RDS backups + point-in-time recovery
- →Deploy circuit-breaker with auto-rollback
- →Fail-closed migrations (no half-migrated boot)
Data handling & residency
- Customer data is hosted in AWS GovCloud (us-gov-west-1), the isolated US-government cloud region, with CUI workloads inside the GovCloud boundary.
- Each organization's data is isolated; one tenant can never query another's.
- You can request export or deletion of your organization's data (GDPR/CCPA rights honored — see the Privacy Policy).
- AI requests send only the context needed for that task; your data is never used to train shared models.
Subprocessors
- Amazon Web Services (AWS GovCloud)Cloud hosting, database, storage (us-gov-west-1)
- StripeSubscription billing + payments (PCI-DSS Level 1)
- Amazon Bedrock (AWS GovCloud)AI generation (RFP parsing, drafting, assistant) inside the GovCloud boundary — no external-LLM egress
- Amazon SES / WorkMailTransactional + branded email
Running a vendor security review?
Tell us what your security or contracting team needs — our NIST 800-171 mapping, the SOC 2 report when it lands, a completed security questionnaire (SIG/CAIQ), or a DPA — and we'll get it to you.