sha3:401e0752e0a17e911dea3dbba4c03b80e0c7840d6a69fe40b3779f34db5ce03cIntactSECURITY / POSTURE RECORD
Posture, attestations, operational reality.
PolicyCortex runs inside the customer's tenant. There is no telemetry pipeline to PolicyCortex servers and no egress of evidence. Every record is SHA3-256 hashed and chained, so a second party can verify it by recomputation. Cryptography uses FIPS 140-3 validated modules. SOC 2 Type II is in progress and FedRAMP Moderate is planned; neither is held today.
84b2c2af10e123c108b4f739e4167813ca883fc3dde3908cc05e0e1863bc28a0prev:0b3404a8c65cIt runs where your data already is
PolicyCortex evaluates policy, collects evidence and gates autonomous action inside your tenant. Nothing about your environment leaves it for us to work. There is no telemetry pipeline pointed at our servers, because a company whose product is proof should not be asking you to trust an outbound connection.
Observed clouds: Azure, AWS, and GCP, including AWS GovCloud, Azure Government, and GCC High. What is not connected is not observed, and the record says so.
- boundary.compute
- Policy evaluation, evidence collection, and action gating run inside the customer tenant.
- boundary.egress
- No telemetry pipeline to PolicyCortex servers. No egress of evidence.
- boundary.regions
- Azure, AWS, and GCP, including AWS GovCloud, Azure Government, and GCC High.
- boundary.data
- Configuration metadata only. No PHI, no CUI, no PII: cloud APIs return resource state, not data.
fa2aa4f7e1fa379fdced6e16b368c7c78ed7e49e073596b415afea1f6e429691prev:84b2c2af10e1Evidence you can recompute
Each record digest is SHA3-256 over the record content plus the previous record digest. Streams are append-only; there is no update or delete verb in the store. Verification is a recomputation: it returns INTACT, or the first sequence number where integrity fails. A second party can run it with no PolicyCortex account or API in the loop.
Absence is recorded as a declared gap (stream, interval, reason, declared_at), chained like everything else. Exported evidence packages are AES-256 protected. The record headers on this page are built the same way; the colophon below shows the chain.
The architecture, written for the person whose job is to disbelieve it.
5db17e8b2948ee5768f9b1749ff1a80da01c06f398c7731fd65cd273b6e261e5prev:fa2aa4f7e1faAttestations, at their real stage
Attestations at their real stage, not rounded up. This record changes when the stage does.
- soc2.type2
- In progress. Auditor engaged.
- fedramp
- Moderate path. Planned, not held.
- cryptography
- FIPS 140-3 validated modules.
- deployment
- GovCloud and GCC High available.
62d8be7060179ae16316586a86fcad6552ff206217905850ab41b6ac2db3654bprev:5db17e8b2948Six practices
Six practices, stated plainly. Each is checkable in a security review.
- P-01
Least privilege by default
Cloud accounts onboarded with read-only scope; write scope per action class.
- P-02
Tamper-evident audit log
Every platform action content-hashed; the chain is verifiable independent of PolicyCortex.
- P-03
No PHI, no CUI, no PII
We process configuration metadata only. Cloud APIs return resource state, not data.
- P-04
SBOM, SAST, and DAST
Continuous supply chain scanning. Dependency vulnerabilities tracked and patched.
- P-05
Annual penetration test
Independent third-party penetration testing on the production platform.
- P-06
Incident response procedures
Documented IR runbook. 24-hour notification SLA. Customer-facing security report.
401e0752e0a17e911dea3dbba4c03b80e0c7840d6a69fe40b3779f34db5ce03cprev:62d8be706017Questionnaires and disclosures
Have a security questionnaire (SIG-Lite, CAIQ, custom)? Email [email protected]. We respond within one business day.
Vulnerability reports and data-processing questions follow the disclosure policy.
Bring the questionnaire. We answer with the record.