Security practices guide

How Bedrock CMMC protects your data

We treat all customer data as Controlled Unclassified Information (CUI). Even when your data may not carry a formal CUI designation, we apply the full rigor of NIST SP 800-171 and CMMC Level 2 controls to everything on the platform.

110/110

CMMC practices

14/14

Control domains

AES-256

Encryption at rest

TLS 1.3

Encryption in transit

365 days

Audit log retention

Zero Trust

Architecture

Our commitment

We don't treat customer data casually.

An attacker with access to your compliance documentation would have a roadmap to your security gaps. Access is restricted to authenticated, authorized users with a legitimate need. Data is encrypted in transit and at rest using FIPS-validated cryptographic modules. All access is logged and auditable. Data isolation is enforced at the application and database layer — your data is never commingled with another organization's.

Architecture

Platform architecture

Defense-in-depth at every layer, built on FedRAMP Moderate authorized infrastructure.

Public tier

Only the Application Load Balancer faces the internet. No application servers or databases are internet-accessible. All traffic enters through HTTPS only.

Application tier

Containerized services on AWS Fargate with no direct internet access. Each container runs in its own Firecracker microVM with read-only filesystems and non-root execution.

Data tier

Aurora PostgreSQL in private subnets with zero internet access. All connections require TLS and IAM authentication — no database passwords stored anywhere.

Serverless & immutable

  • No servers to manage or patch — AWS manages host infrastructure
  • Firecracker microVM isolation — no shared kernel with other tenants
  • Non-root containers (UID 1001) with privilege escalation disabled
  • Read-only filesystem — no runtime modifications possible

Network isolation

  • Three-tier VPC with deny-all-by-default security groups
  • VPC endpoints for all AWS service calls — never touches public internet
  • Traffic allowed only on specific ports between specific tiers
  • No SSH, RDP, or management ports exposed on any resource

Encryption

Encryption everywhere

Every byte of customer data is encrypted, whether it's moving between services or sitting in storage. No exceptions.

In transit

  • TLS 1.2 minimum, TLS 1.3 preferred for all connections
  • HTTP never accepted — all requests redirected to HTTPS
  • Service-to-service communication encrypted via ECS Service Connect
  • Database connections encrypted with mandatory TLS
  • AWS API calls through encrypted VPC endpoints (PrivateLink)

At rest

  • Aurora PostgreSQL: AES-256 via customer-managed KMS key
  • S3 evidence storage: SSE-KMS encryption with versioning
  • Audit logs: SSE-KMS with Object Lock (WORM) — tamper-proof
  • Secrets Manager: all credentials encrypted with KMS
  • CloudWatch Logs: KMS-encrypted with 365-day retention

Access control

Least privilege at every level

From user authentication to service-to-service calls.

Human access

  • AWS IAM Identity Center (SSO) with mandatory MFA
  • No long-lived access keys — session tokens expire
  • No SSH, RDP, or direct management ports

Service access

  • Dedicated IAM roles per service with minimum permissions
  • CI/CD via OIDC federation — no stored AWS credentials
  • RDS Proxy with IAM auth — no passwords in code

Application access

  • HTTPS authentication with time-limited JWT tokens
  • 8-hour session expiry, 15-minute inactivity timeout
  • Role-based authorization on all API endpoints

Multi-factor authentication — mandatory

Every user on Bedrock CMMC is required to use MFA — no exceptions. Customers, administrators, and external assessors all authenticate with TOTP from any standard authenticator app. Infrastructure access through IAM Identity Center also requires MFA. We do not support SMS as a sole MFA factor due to known SIM-swapping vulnerabilities.

Compromised passwords are the leading cause of unauthorized access. MFA ensures that even if a password is stolen, an attacker cannot access the platform without physical possession of the user's authentication device.

Monitoring

Continuous monitoring

Security is not a one-time configuration — it's a continuous practice.

AWS CloudTrail

Records every API call with log file integrity validation.

Amazon GuardDuty

Continuously analyzes CloudTrail, VPC Flow Logs, and DNS logs for malicious activity.

AWS Security Hub

Aggregates findings from all security services and scores posture against benchmarks.

AWS Config

Evaluates resource configurations against 50+ FedRAMP Moderate conformance rules.

VPC Flow Logs

Captures all network traffic metadata for forensic analysis.

Immutable audit trail

S3 Object Lock (WORM) — logs cannot be modified or deleted, even by administrators.

Incident response

Foxx Cyber maintains a documented Incident Response Plan with defined roles, escalation paths, containment procedures, and communication protocols. We conduct tabletop exercises and review the plan annually. If a security event affects customer data, we are committed to transparent and timely notification.

Compliance posture

We hold ourselves to the same standard.

We built Bedrock CMMC to the same CMMC Level 2 standard we help our customers achieve.

CMMC Level 2

All 110 CMMC Level 2 security practices implemented across 14 control domains. These practices are documented in domain-specific policies and procedures, with technical evidence maintained for each control.

NIST SP 800-171 Rev. 2

Our System Security Plan documents how each of the 110 security requirements is satisfied through implemented controls, inherited AWS capabilities, or documented plans of action.

Compliance FrameworkCMMC 2.11 Level 2NIST AlignmentSP 800-171 Rev. 2
InfrastructureAWS FedRAMP ModeratePractices Implemented110 of 110
Domains Covered14 of 14Review CycleAnnual (next: March 2027)

FedRAMP Moderate inheritance

  • 21 controls fully inherited from AWS
  • 79 shared responsibility
  • 10 managed by Foxx Cyber

Your trust is our authority to operate.

Questions about our security practices? We're happy to discuss in detail.