Security

The regulation requires a CRM. We’re going further.

The DoD's CMMC regulation, 32 CFR §170.19(c)(2), asks a provider like Garde1 for a service description and a customer responsibility matrix, and the compliance packet has both. Hosted on FedRAMP Moderate authorized AWS services in us-east-2. Garde1 itself is not FedRAMP authorized. GovCloud is on the roadmap. Full FedRAMP 20x authorization is on the roadmap too. None of it is required by the regulation. All of it is what serious DIB buyers eventually ask for, so we're not waiting to be asked.

Garde1 protects your scope, your System Security Plan (SSP) drafts, and your connector-derived posture, and never CUI. Sign-in runs on Amazon Cognito. New to CMMC? Start with the plain-English explainer →

Garde1 has not had a third-party penetration test; the date will be posted here when one is scheduled.

Principles

Zero trust. Least privilege. Privacy by design.

Zero trust

Every request authenticated, every action audited.

Nothing inside Garde1 is implicitly trusted because it's “already in the network.” Every API call is identity-bound (Amazon Cognito OIDC), tenant-scoped at two layers (per-transaction organization scoping + database row-level security), and short-lived (15-minute access tokens). Every change is recorded in an append-only audit log kept for seven years.

Least privilege

The minimum permissions to do the job. Nothing more.

Connectors run read-only by default. Write access needs a separate credential per connector, and each action is checked against the permissions you granted. ECS tasks use scoped IAM roles; production secrets live in AWS Secrets Manager and never appear in code.

Privacy by design

We don't collect what we don't need.

Garde1 doesn't ask for or accept CUI in the commercial product. Connectors collect configuration and security metadata — never end-user files, mail, or chat content. Connector data is stored as the source system returns it, encrypted at rest, isolated per organization. Your data is not used to train AI models.

The stack

Five stages. Edge → Identity → Tenancy → Data → Trail.

A request to Garde1 passes through five named control stages before it ever touches your data — and every change leaves an audit record on the way out. Each stage groups the controls that operate there.

1 — Edge

HTTPS only, behind a CDN. Cloudflare fronts the app, the API and garde1.com, with Amazon CloudFront behind it. Plain HTTP redirects.

2 — Identity

Cognito sign-in, Garde1-side MFA, short sessions. OIDC through Amazon Cognito with Microsoft, Google and per-organization SAML; Garde1 serves SCIM itself. A Garde1 gate demands a TOTP or single-use backup code before any session exists, whatever the identity provider asserted. Access tokens live 15 minutes; sessions at most 8 hours.

3 — Tenancy

Two independent layers of isolation. Every database transaction is scoped to the caller's organization, and Postgres row-level security is forced on about 190 tables, so a query has to satisfy both to return a row. ECS tasks use scoped IAM roles; production credentials live in AWS Secrets Manager, never in code.

4 — Data

Validated on ingest, isolated per organization, encrypted at rest. Connector evidence is authenticated to its organization, schema-checked against the vendor and control mapping, then tenant-tagged behind the same row-level security as every read. Aurora PostgreSQL is encrypted with an AWS KMS key, requires TLS, and accepts connections only from Garde1's services and one allowlisted administrator address. Document buckets block public access. Connector credentials sit in Secrets Manager, not the database.

5 — Trail

Append-only audit log, backups, public status. Every state-changing action lands in an append-only log kept seven years with deletion protection and 35-day point-in-time recovery, which Aurora has too; the documents bucket is versioned. Every monitored endpoint and worker reports in real time at status.garde1.com.

In depth

AI, connectors, CUI. One page each.

FedRAMP building blocks

Built on FedRAMP Moderate-authorized AWS services, in us-east-2.

The AWS services in Garde1's production path carry FedRAMP Moderate authorization in the AWS US East / West boundary.

This is the distinction buyers care about most. Building blocks — the AWS services Garde1 runs on — are individually FedRAMP Moderate authorized today. The full-system package goes through its own FedRAMP 20x authorization on the roadmap.

The AWS services Garde1 runs on, each on the AWS FedRAMP services-in-scope list:

Garde1 usesFedRAMP Moderate (East / West)
Aurora PostgreSQLAuthorized
Amazon ECS on FargateAuthorized
Amazon S3Authorized
Amazon SQSAuthorized
AWS LambdaAuthorized
Amazon DynamoDBAuthorized
Amazon CloudFrontAuthorized
Amazon CognitoAuthorized
Amazon ElastiCache (Valkey)Authorized
Amazon EFSAuthorized
AWS Secrets ManagerAuthorized
AWS KMSAuthorized
Amazon SESAuthorized
AWS BackupAuthorized
AWS Systems ManagerAuthorized
Amazon CloudWatchAuthorized
Amazon EventBridgeAuthorized
The road from here

Today FedRAMP Moderate AWS. Tomorrow GovCloud. After that, FedRAMP 20x.

Each phase below has a defined trigger and a measurable outcome. Shipping each one is how we prove our security posture isn't aspirational.

  1. Phase 1Today

    FedRAMP Moderate AWS, US region

    The platform runs on FedRAMP Moderate-authorized AWS services in us-east-2. Your data is encrypted at rest, the database isolates rows per organization, every sign-in requires a second factor (authenticator app or backup code), vendor credentials live in AWS Secrets Manager, and every change lands in an append-only audit log kept seven years. Garde1 never asks for or holds CUI — these controls protect your scope, evidence, and connector credentials.

  2. Phase 2Planned

    AWS GovCloud (US) tenancy

    A dedicated aws-us-gov partition deployment for customers whose contracts demand U.S.-person-only operator access and a GovCloud-resident control plane.

  3. Phase 3Planned

    FedRAMP 20x authorization

    Full-system authorization through the streamlined FedRAMP 20x process. The GovCloud tenancy from Phase 2 is the assessment boundary; the building blocks are already authorized. This phase wraps the composed platform in its own package.

Responsible disclosure

Found something? Tell us first.

Send reproduction steps using the form below. We acknowledge reports within one business day and commit to a substantive response within five business days. We will not pursue legal action against good-faith security research that follows reasonable disclosure norms.

One business day · No sales drip

Need it on one page for a security review? Download the data-handling summary (PDF).