Security

Security is the product, not a feature.

GridTailor is built to NIST SP 800-171 controls from the first line of code, so a prime contractor can flow requirements down to us without a rewrite.

How we protect your data

Isolation

Separate AWS accounts per environment with organization guardrails. Every record is keyed to your tenant, and tenant identity comes only from your verified sign-in.

Identity

Multi-factor authentication is required. Access is invite-only, and sessions lock after 15 minutes of inactivity. We use no long-lived cloud access keys.

Encryption

TLS in transit. AWS KMS encryption at rest, with per-tenant envelope encryption for stored record payloads. AWS calls use FIPS 140-validated endpoints.

Audit

Every change is recorded in a per-tenant, hash-chained audit log written in the same transaction as the change. AWS API activity is logged to a separate security account.

Least privilege

Workloads run with narrowly scoped roles behind a permissions boundary. AI tools are read-only.

Secure delivery

Infrastructure is code, and every change is peer reviewed. CI scans for secrets and insecure infrastructure before anything ships.

Compliance posture

  • Engineered against NIST SP 800-171 Rev. 2, with a control-by-control implementation matrix.
  • Hosted on AWS commercial regions (US East). A GovCloud (US) environment is planned for customers who need it.
  • Data classification (public, internal, confidential, CUI) controls where data and AI may go.
  • Incident response plan covering the DFARS 252.204-7012 72-hour reporting requirement.

GridTailor has not yet completed a third-party CMMC assessment. We'll share our control matrix and security documentation under NDA.

Report a vulnerability

Email security@gridtailor.com. Please give us a reasonable time to fix the issue before you disclose it. We won't pursue good-faith research that avoids privacy violations and service disruption.

Need our security documentation?

Book a call and we'll walk your security team through it.