The regulation requires a CRM. We’re going further.
The DoD's CMMC regulation, 32 CFR §170.19(c)(2), asks a provider like Garde1 for a service description and a customer responsibility matrix, and the compliance packet has both. Hosted on FedRAMP Moderate authorized AWS services in us-east-2. Garde1 itself is not FedRAMP authorized. GovCloud is on the roadmap. Full FedRAMP 20x authorization is on the roadmap too. None of it is required by the regulation. All of it is what serious DIB buyers eventually ask for, so we're not waiting to be asked.
Garde1 protects your scope, your System Security Plan (SSP) drafts, and your connector-derived posture, and never CUI. Sign-in runs on Amazon Cognito. New to CMMC? Start with the plain-English explainer →
Garde1 has not had a third-party penetration test; the date will be posted here when one is scheduled.
Zero trust. Least privilege. Privacy by design.
Every request authenticated, every action audited.
Nothing inside Garde1 is implicitly trusted because it's “already in the network.” Every API call is identity-bound (Amazon Cognito OIDC), tenant-scoped at two layers (per-transaction organization scoping + database row-level security), and short-lived (15-minute access tokens). Every change is recorded in an append-only audit log kept for seven years.
The minimum permissions to do the job. Nothing more.
Connectors run read-only by default. Write access needs a separate credential per connector, and each action is checked against the permissions you granted. ECS tasks use scoped IAM roles; production secrets live in AWS Secrets Manager and never appear in code.
We don't collect what we don't need.
Garde1 doesn't ask for or accept CUI in the commercial product. Connectors collect configuration and security metadata — never end-user files, mail, or chat content. Connector data is stored as the source system returns it, encrypted at rest, isolated per organization. Your data is not used to train AI models.
Five stages. Edge → Identity → Tenancy → Data → Trail.
A request to Garde1 passes through five named control stages before it ever touches your data — and every change leaves an audit record on the way out. Each stage groups the controls that operate there.
1 — Edge
HTTPS only, behind a CDN. Cloudflare fronts the app, the API and garde1.com, with Amazon CloudFront behind it. Plain HTTP redirects.
2 — Identity
Cognito sign-in, Garde1-side MFA, short sessions. OIDC through Amazon Cognito with Microsoft, Google and per-organization SAML; Garde1 serves SCIM itself. A Garde1 gate demands a TOTP or single-use backup code before any session exists, whatever the identity provider asserted. Access tokens live 15 minutes; sessions at most 8 hours.
3 — Tenancy
Two independent layers of isolation. Every database transaction is scoped to the caller's organization, and Postgres row-level security is forced on about 190 tables, so a query has to satisfy both to return a row. ECS tasks use scoped IAM roles; production credentials live in AWS Secrets Manager, never in code.
4 — Data
Validated on ingest, isolated per organization, encrypted at rest. Connector evidence is authenticated to its organization, schema-checked against the vendor and control mapping, then tenant-tagged behind the same row-level security as every read. Aurora PostgreSQL is encrypted with an AWS KMS key, requires TLS, and accepts connections only from Garde1's services and one allowlisted administrator address. Document buckets block public access. Connector credentials sit in Secrets Manager, not the database.
5 — Trail
Append-only audit log, backups, public status. Every state-changing action lands in an append-only log kept seven years with deletion protection and 35-day point-in-time recovery, which Aurora has too; the documents bucket is versioned. Every monitored endpoint and worker reports in real time at status.garde1.com.
AI, connectors, CUI. One page each.
Not used for training.
Which model providers Garde1 uses, what data they see, what they can’t see, and the contractual terms that keep your evidence out of model-training corpora.
Connector scopesRead-only by default. Write only on request.
Read-only by default. Write access only with a separate permission you grant; scopes are shown in the product before you consent.
No-CUIWhy Garde1 doesn’t hold CUI.
Architecture and policy guarantees that keep CUI out of the commercial platform, written for assessors and prime-contractor security reviews.
Built on FedRAMP Moderate-authorized AWS services, in us-east-2.
This is the distinction buyers care about most. Building blocks — the AWS services Garde1 runs on — are individually FedRAMP Moderate authorized today. The full-system package goes through its own FedRAMP 20x authorization on the roadmap.
The AWS services Garde1 runs on, each on the AWS FedRAMP services-in-scope list:
| Garde1 uses | FedRAMP Moderate (East / West) |
|---|---|
| Aurora PostgreSQL | Authorized |
| Amazon ECS on Fargate | Authorized |
| Amazon S3 | Authorized |
| Amazon SQS | Authorized |
| AWS Lambda | Authorized |
| Amazon DynamoDB | Authorized |
| Amazon CloudFront | Authorized |
| Amazon Cognito | Authorized |
| Amazon ElastiCache (Valkey) | Authorized |
| Amazon EFS | Authorized |
| AWS Secrets Manager | Authorized |
| AWS KMS | Authorized |
| Amazon SES | Authorized |
| AWS Backup | Authorized |
| AWS Systems Manager | Authorized |
| Amazon CloudWatch | Authorized |
| Amazon EventBridge | Authorized |
Today FedRAMP Moderate AWS. Tomorrow GovCloud. After that, FedRAMP 20x.
Each phase below has a defined trigger and a measurable outcome. Shipping each one is how we prove our security posture isn't aspirational.
- Phase 1Today
FedRAMP Moderate AWS, US region
The platform runs on FedRAMP Moderate-authorized AWS services in us-east-2. Your data is encrypted at rest, the database isolates rows per organization, every sign-in requires a second factor (authenticator app or backup code), vendor credentials live in AWS Secrets Manager, and every change lands in an append-only audit log kept seven years. Garde1 never asks for or holds CUI — these controls protect your scope, evidence, and connector credentials.
- Phase 2Planned
AWS GovCloud (US) tenancy
A dedicated
aws-us-govpartition deployment for customers whose contracts demand U.S.-person-only operator access and a GovCloud-resident control plane. - Phase 3Planned
FedRAMP 20x authorization
Full-system authorization through the streamlined FedRAMP 20x process. The GovCloud tenancy from Phase 2 is the assessment boundary; the building blocks are already authorized. This phase wraps the composed platform in its own package.
Found something? Tell us first.
Send reproduction steps using the form below. We acknowledge reports within one business day and commit to a substantive response within five business days. We will not pursue legal action against good-faith security research that follows reasonable disclosure norms.
Need it on one page for a security review? Download the data-handling summary (PDF).