Row-level security on every participant table
Policies scope each row to the owning workspace and the caller's role. Access is denied by default; a table with no policy returns nothing.
Security & compliance
Compass AI holds participant records, PIRL demographics and UI wage data. Each safeguard below is implemented in the product today and mapped to the NIST SP 800-53 Rev. 5 controls that state data-sharing agreements cite. Administrators can export live control status from inside their workspace.
Where we stand: hardened multi-tenant hosting with row-level isolation is the standard deployment. AWS GovCloud (US) single-tenant deployment is available as an add-on. StateRAMP Moderate artifacts are maintained and continuous monitoring is running; the authorization itself is not yet granted, and we will not claim otherwise in a procurement response.
Every participant record is scoped by workspace and by role at the database layer, not in application code, so a direct query cannot escape its workspace.
Policies scope each row to the owning workspace and the caller's role. Access is denied by default; a table with no policy returns nothing.
Administrator, program staff and case manager permission groups, plus workspace-defined custom roles that grant only named modules.
PIRL demographics, eligibility detail, TAA records and SSNs require an explicit sensitive-data permission that case-file access never implies.
Cohort and board rollups are de-identified server-side; drill-down to a named participant requires case-file authority.
Staff authentication meets the NIST SP 800-63B AAL2 expectations that state agencies apply to WIOA case data.
Multi-factor enrollment is tracked per account and surfaced in the controls dashboard, with protected-data use blocked when coverage lapses.
Opt-in per workspace with domain routing, so an agency can require its own identity provider without affecting other workspaces.
Invitations are single-use, expiring, one-click links that require the recipient to establish a password before any data is visible.
Wage data and participant records carry the audit trail that 20 CFR Part 603 and state data-sharing agreements require.
Every UI-wage query records requester, purpose, scope and result count, with search, filters and a privacy summary of what was returned.
A recurring sweep flags query spikes and unusual access patterns and notifies administrators automatically.
Posting status changes, case-file edits, AI-drafted versus human-edited fields, and fiscal approvals are all attributed and timestamped.
The system collects the least identifying data that federal reporting allows, and deletes it on a schedule you set.
SSNs are stored encrypted and separated from the case record, readable only with the sensitive-data permission.
Alternate matching identifiers can replace SSN collection entirely, and a daily sweep purges SSNs on your configured retention schedule.
TLS everywhere, and state-system integration credentials held in an AES-256-GCM vault that never returns plaintext to the browser.
Security posture is verified on every build rather than at annual review.
Automated tests cover every previously fixed access-control finding so a regression fails the build instead of shipping.
A scheduled job reconciles the live database grants and policies against the expected baseline and alerts on drift.
Rules predict likely federal monitor findings, attach a remediation playbook, track SLA due dates and offer verified one-click fixes.
The standard subscription runs on a hardened multi-tenant environment. Agencies with stricter requirements can move to a dedicated deployment.
Terraform landing zone with WAF, Shield, GuardDuty and Inspector, mapped to NIST 800-53 Moderate. Available as a dedicated add-on tenancy.
System security plan, POA&M and automated evidence generation are maintained against the StateRAMP Moderate baseline. Authorization is not yet granted.
Point-in-time recovery on the managed database, plus a full WIPS/PIRL-format export you can run yourself at any time, including on exit.
Download a pre-filled security questionnaire mapped to NIST SP 800-53, an overview of every audit trail the system keeps, and our incident-response summary — no call required.
Open trust resources