Security & compliance

Controls your monitors can verify, not a trust badge

Compass AI holds participant records, PIRL demographics and UI wage data. Each safeguard below is implemented in the product today and mapped to the NIST SP 800-53 Rev. 5 controls that state data-sharing agreements cite. Administrators can export live control status from inside their workspace.

Where we stand: hardened multi-tenant hosting with row-level isolation is the standard deployment. AWS GovCloud (US) single-tenant deployment is available as an add-on. StateRAMP Moderate artifacts are maintained and continuous monitoring is running; the authorization itself is not yet granted, and we will not claim otherwise in a procurement response.

Access control and tenant isolation

Every participant record is scoped by workspace and by role at the database layer, not in application code, so a direct query cannot escape its workspace.

AC-3AC-4In place

Row-level security on every participant table

Policies scope each row to the owning workspace and the caller's role. Access is denied by default; a table with no policy returns nothing.

AC-2AC-6In place

Least privilege by role and custom role builder

Administrator, program staff and case manager permission groups, plus workspace-defined custom roles that grant only named modules.

AC-6(1)In place

Sensitive data is a separate permission

PIRL demographics, eligibility detail, TAA records and SSNs require an explicit sensitive-data permission that case-file access never implies.

AC-21In place

De-identification in cohort analytics

Cohort and board rollups are de-identified server-side; drill-down to a named participant requires case-file authority.

Identification and authentication

Staff authentication meets the NIST SP 800-63B AAL2 expectations that state agencies apply to WIOA case data.

IA-2IA-2(1)In place

MFA for staff accounts

Multi-factor enrollment is tracked per account and surfaced in the controls dashboard, with protected-data use blocked when coverage lapses.

IA-8In place

Agency SSO (SAML 2.0)

Opt-in per workspace with domain routing, so an agency can require its own identity provider without affecting other workspaces.

IA-5In place

Password establishment and invite hardening

Invitations are single-use, expiring, one-click links that require the recipient to establish a password before any data is visible.

Audit and accountability

Wage data and participant records carry the audit trail that 20 CFR Part 603 and state data-sharing agreements require.

AU-2AU-3In place

Wage-access audit log

Every UI-wage query records requester, purpose, scope and result count, with search, filters and a privacy summary of what was returned.

AU-6SI-4In place

Anomaly detection on wage access

A recurring sweep flags query spikes and unusual access patterns and notifies administrators automatically.

AU-12CM-5In place

Change and status audit trails

Posting status changes, case-file edits, AI-drafted versus human-edited fields, and fiscal approvals are all attributed and timestamped.

Data protection and minimization

The system collects the least identifying data that federal reporting allows, and deletes it on a schedule you set.

SC-28In place

Encrypted identifiers at rest

SSNs are stored encrypted and separated from the case record, readable only with the sensitive-data permission.

SI-12PT-2In place

Policy-driven SSN minimization and purge

Alternate matching identifiers can replace SSN collection entirely, and a daily sweep purges SSNs on your configured retention schedule.

SC-8SC-13In place

Encryption in transit and credential vault

TLS everywhere, and state-system integration credentials held in an AES-256-GCM vault that never returns plaintext to the browser.

Secure development and continuous monitoring

Security posture is verified on every build rather than at annual review.

CM-3SA-11In place

Security regression suite in CI

Automated tests cover every previously fixed access-control finding so a regression fails the build instead of shipping.

CM-6In place

Access-control and exposure drift watch

A scheduled job reconciles the live database grants and policies against the expected baseline and alerts on drift.

CA-7In place

Proactive audit-readiness engine

Rules predict likely federal monitor findings, attach a remediation playbook, track SLA due dates and offer verified one-click fixes.

Hosting and authorization

The standard subscription runs on a hardened multi-tenant environment. Agencies with stricter requirements can move to a dedicated deployment.

SC-7SA-9Available on request

AWS GovCloud (US) reference deployment

Terraform landing zone with WAF, Shield, GuardDuty and Inspector, mapped to NIST 800-53 Moderate. Available as a dedicated add-on tenancy.

CA-2CA-6In progress

StateRAMP Moderate authorization

System security plan, POA&M and automated evidence generation are maintained against the StateRAMP Moderate baseline. Authorization is not yet granted.

CP-9CP-10In place

Backup, recovery and data portability

Point-in-time recovery on the managed database, plus a full WIPS/PIRL-format export you can run yourself at any time, including on exit.

Questions from your RFP

Where does our data live, and who can see it?
In a dedicated managed Postgres database with row-level security scoping every table to your workspace. Support staff cannot query participant data; troubleshooting runs on de-identified diagnostics.
Are you FedRAMP or StateRAMP authorized?
Not yet. We maintain the StateRAMP Moderate artifact set — SSP, POA&M and automated evidence — and offer a dedicated AWS GovCloud (US) tenancy today for agencies that require it contractually.
How do you handle UI wage records under 20 CFR Part 603?
Wage access is permission-gated, purpose-logged, de-identified in aggregate views, and monitored for query spikes. The audit log is exportable for your own monitors.
Can we avoid giving you Social Security numbers?
Yes. Alternate matching identifiers can be used instead, and a workspace preference blocks SSN collection outright when alternatives are on file.
What happens to our data if we leave?
You export the full record set in WIPS/PIRL format at any time. On termination we delete your workspace data on your stated schedule and confirm in writing.
How do you prove controls between audits?
The in-product controls dashboard evaluates each safeguard live and produces a buyer-ready evidence export, so you can attach current status to your own monitoring package.

Trust resources

Download a pre-filled security questionnaire mapped to NIST SP 800-53, an overview of every audit trail the system keeps, and our incident-response summary — no call required.

Open trust resources