Security
Security is the product, not a feature.
GridTailor is built to NIST SP 800-171 controls from the first line of code, so a prime contractor can flow requirements down to us without a rewrite.
How we protect your data
Isolation
Separate AWS accounts per environment with organization guardrails. Every record is keyed to your tenant, and tenant identity comes only from your verified sign-in.
Identity
Multi-factor authentication is required. Access is invite-only, and sessions lock after 15 minutes of inactivity. We use no long-lived cloud access keys.
Encryption
TLS in transit. AWS KMS encryption at rest, with per-tenant envelope encryption for stored record payloads. AWS calls use FIPS 140-validated endpoints.
Audit
Every change is recorded in a per-tenant, hash-chained audit log written in the same transaction as the change. AWS API activity is logged to a separate security account.
Least privilege
Workloads run with narrowly scoped roles behind a permissions boundary. AI tools are read-only.
Secure delivery
Infrastructure is code, and every change is peer reviewed. CI scans for secrets and insecure infrastructure before anything ships.
Compliance posture
- Engineered against NIST SP 800-171 Rev. 2, with a control-by-control implementation matrix.
- Hosted on AWS commercial regions (US East). A GovCloud (US) environment is planned for customers who need it.
- Data classification (public, internal, confidential, CUI) controls where data and AI may go.
- Incident response plan covering the DFARS 252.204-7012 72-hour reporting requirement.
GridTailor has not yet completed a third-party CMMC assessment. We'll share our control matrix and security documentation under NDA.
Report a vulnerability
Email security@gridtailor.com. Please give us a reasonable time to fix the issue before you disclose it. We won't pursue good-faith research that avoids privacy violations and service disruption.
Need our security documentation?
Book a call and we'll walk your security team through it.