Security & compliance

Trust resources

Everything your vendor review asks for, in one download

A pre-filled security questionnaire, an overview of what the audit log captures, and a summary of how we respond to an incident. Published by the operator of Compass AI and current as of version 2026-08. This is not an independent audit report or a certification — where a commitment is contractual, we point to your agreement instead of restating terms.

Security questionnaire

Answers are mapped to NIST SP 800-53 Rev. 5 controls so your reviewer can drop them straight into a control matrix.

Governance and certifications

GOV-1Do you hold a FedRAMP or StateRAMP authorization?
No authorization is granted today. The StateRAMP Moderate artifact set — system security plan, POA&M and automated evidence generation — is maintained and continuous monitoring is running. We will not represent an authorization we do not hold.
CA-2CA-6
GOV-2Which control framework do you map to?
NIST SP 800-53 Rev. 5 at the Moderate baseline, with staff authentication aligned to NIST SP 800-63B AAL2. Each published safeguard on the security page carries its control identifiers.
PM-9CA-7
GOV-3Can we see live control status rather than a point-in-time attestation?
Yes. Workspace administrators run the in-product controls dashboard, which evaluates each safeguard against the live environment and produces an evidence export you can attach to your own monitoring package.
CA-7AU-6

Access control and tenant isolation

AC-1QHow is one agency's data isolated from another's?
Isolation is enforced at the database layer with row-level security, not in application code. Every participant, plan, service and fiscal row is scoped to its owning workspace and to the caller's role. Tables deny by default: a table without a matching policy returns no rows to a direct query.
AC-3AC-4SC-4
AC-2QHow are roles and permissions defined?
Administrator, program staff and case manager permission groups ship by default, and each workspace can define custom roles that grant only named modules. Role assignment and changes are performed by workspace administrators and recorded.
AC-2AC-6
AC-3QIs sensitive participant data separated from general case access?
Yes. PIRL demographics, eligibility detail, barrier flags, TAA records and Social Security numbers require an explicit sensitive-data permission that case-file access never implies. The same restriction applies to the AI case assistant's grounding context.
AC-6(1)AC-21
AC-4QCan your support staff read our participant records?
Routine troubleshooting runs on de-identified diagnostics. Any access to identified records is performed under your workspace's own accounts and policies and is captured in the audit trail.
AC-6AU-2

Identity and authentication

IA-1QIs multi-factor authentication supported and enforceable?
Yes. MFA enrollment is tracked per staff account and surfaced in the controls dashboard, and protected-data workflows are blocked when coverage lapses.
IA-2IA-2(1)
IA-2QCan we use our own identity provider?
Yes. SAML 2.0 single sign-on is opt-in per workspace with email-domain routing, so an agency can require its own IdP without affecting other workspaces on the platform.
IA-8
IA-3QHow are new staff accounts provisioned?
By invitation only. Invites are single-use, expiring, one-click links that require the recipient to establish a password before any workspace data is visible. Expired, revoked and already-used links are refused with a clear reason.
IA-5AC-2

Data protection, minimization and retention

DP-1QHow is data encrypted?
TLS protects data in transit. Social Security numbers are stored encrypted and separated from the case record. State-system integration credentials are held in an AES-256-GCM vault that never returns plaintext to the browser.
SC-8SC-13SC-28
DP-2QCan we avoid providing Social Security numbers at all?
Yes. Alternate matching identifiers can be used in place of SSN, and a workspace preference blocks SSN collection outright when alternatives are on file.
PT-2SI-12
DP-3QHow long is identifying data retained?
Retention is configured per workspace. A daily sweep purges SSNs on the schedule you set. Program records are retained for the period your grant and state record-retention requirements specify, as stated in your agreement.
SI-12AU-11
DP-4QHow do you handle UI wage records under 20 CFR Part 603?
Wage access is permission-gated and purpose-logged, aggregate views are de-identified server-side, and query volume is monitored for spikes. The wage-access audit log is searchable and exportable for your own monitors.
AC-21AU-2AU-6
DP-5QWhat happens to our data if we terminate?
You can export the full record set in WIPS/PIRL format at any time, including on exit. After termination, workspace data is deleted on the schedule stated in your agreement and the deletion is confirmed in writing.
CP-9MP-6

Operations, monitoring and resilience

OP-1QHow is security verified between audits?
An automated security regression suite covers every previously fixed access-control finding and fails the build on regression. A scheduled drift watch reconciles live database grants and policies against the expected baseline and alerts on divergence.
CM-3CM-6SA-11
OP-2QDo you monitor for anomalous access?
Yes. A recurring sweep flags wage-query spikes and unusual access patterns and notifies workspace administrators automatically.
SI-4AU-6
OP-3QWhat are your backup and recovery capabilities?
The managed database supports point-in-time recovery. Recovery objectives applicable to your subscription are stated in your agreement; customer-run WIPS/PIRL exports provide an independent copy of the record set at any time.
CP-9CP-10
OP-4QWhere is the system hosted, and is a dedicated environment available?
The standard subscription runs on a hardened multi-tenant managed environment with row-level isolation. A dedicated AWS GovCloud (US) deployment — Terraform landing zone with WAF, Shield, GuardDuty and Inspector, mapped to the NIST 800-53 Moderate baseline — is available as an add-on tenancy.
SC-7SA-9

Audit log overview

Audit records are scoped to the owning workspace by the same row-level policies as participant data and cannot be edited from the application.

Event classWhat is capturedRetentionWho can read it
UI wage-record accessRequester, workspace, stated purpose, query scope, result count, timestampRetained for the period in your data-sharing agreementAdministrators; exportable with search and filters
Sensitive-field reads (SSN, PIRL, TAA)Account, permission used, participant reference, timestampRetained with the participant recordAdministrators with the sensitive-data permission
Case-file and plan editsAccount, field, prior and new value, AI-drafted vs. human-edited provenanceRetained with the participant recordAdministrators, program staff on their caseload
Role and membership changesActor, subject account, role granted or removed, workspace, timestampRetained for the life of the workspaceAdministrators
Fiscal approvals and expendituresRequester, approver (separation of duties enforced), amount, grant, service linkageRetained for the grant record-retention periodAdministrators, fiscal staff
Job posting and application status changesActor, prior and new status, scheduled publish dates, timestampRetained with the postingAdministrators, employer account owners
Integration and credential activityConnection, actor, action, outcome; secret values are never loggedRetained for the life of the connectionAdministrators

Incident-response summary

Notification recipients and timelines are governed by your agreement and applicable state breach-notification law. Report a suspected issue to security@satrde.com.

  1. 1. Detect

    Anomalous access and control drift surface automatically rather than waiting for a report.

    Mechanism: Wage-query spike detection, access-control drift watch against the live database baseline, security regression suite on every build, and dependency scanning.

  2. 2. Triage and classify

    An event is classified by whether protected participant data, UI wage data or credentials were involved, and by the workspaces affected.

    Mechanism: Audit trails identify the accounts, records and workspaces in scope; sensitive-data permissions narrow who could have read what.

  3. 3. Contain

    Access is cut off before root cause is known — sessions revoked, roles reduced, credentials rotated, integrations disabled.

    Mechanism: Per-account role revocation, workspace-scoped policy changes, credential vault rotation, and integration connection disablement.

  4. 4. Notify

    Affected workspace administrators are notified. Notification timelines, recipients and content follow your agreement and applicable state breach-notification law.

    Mechanism: In-product administrator notifications plus the contact path named in your contract. Contractual timelines are not restated here — see your agreement.

  5. 5. Eradicate and recover

    The defect is fixed, the fix is verified against the live environment, and service is restored from a known-good state.

    Mechanism: One-click verified remediation for known finding classes, point-in-time database recovery, and re-run of the affected control checks.

  6. 6. Learn and prevent recurrence

    Every closed incident adds a permanent automated check so the same condition cannot return silently.

    Mechanism: A regression test is added to the security suite for the specific finding, and the audit-readiness rule set is extended where the condition maps to a federal monitor finding.