---
title: "Security Posture"
description: "PolicyCortex security: in-tenant, no evidence egress, SHA3-256 chained records, FIPS 140-3 cryptography, SOC 2 Type II in progress, FedRAMP planned."
url: https://policycortex.com/security
sealed: 2026-09-02
amended: 2026-09-05
register: security
records: 5
digest: sha3:401e0752e0a17e911dea3dbba4c03b80e0c7840d6a69fe40b3779f34db5ce03c
---

# Posture, attestations, operational reality.

SECURITY / POSTURE RECORD

PolicyCortex runs inside the customer's tenant. There is no telemetry pipeline to PolicyCortex servers and no egress of evidence. Every record is SHA3-256 hashed and chained, so a second party can verify it by recomputation. Cryptography uses FIPS 140-3 validated modules. SOC 2 Type II is in progress and FedRAMP Moderate is planned; neither is held today.

[Request Access](https://app.policycortex.com/auth?mode=request-access) · [Read the architecture](https://policycortex.com/architecture)

## It runs where your data already is

PolicyCortex evaluates policy, collects evidence and gates autonomous action inside your tenant. Nothing about your environment leaves it for us to work. There is no telemetry pipeline pointed at our servers, because a company whose product is proof should not be asking you to trust an outbound connection.

Observed clouds: Azure, AWS, and GCP, including AWS GovCloud, Azure Government, and GCC High. What is not connected is not observed, and the record says so.

- **boundary.compute**: Policy evaluation, evidence collection, and action gating run inside the customer tenant.
- **boundary.egress**: No telemetry pipeline to PolicyCortex servers. No egress of evidence.
- **boundary.regions**: Azure, AWS, and GCP, including AWS GovCloud, Azure Government, and GCC High.
- **boundary.data**: Configuration metadata only. No PHI, no CUI, no PII: cloud APIs return resource state, not data.

## Evidence you can recompute

Each record digest is SHA3-256 over the record content plus the previous record digest. Streams are append-only; there is no update or delete verb in the store. Verification is a recomputation: it returns INTACT, or the first sequence number where integrity fails. A second party can run it with no PolicyCortex account or API in the loop.

Absence is recorded as a declared gap (stream, interval, reason, declared_at), chained like everything else. Exported evidence packages are AES-256 protected. The record headers on this page are built the same way; the colophon below shows the chain.

[The architecture, written for the person whose job is to disbelieve it.](https://policycortex.com/architecture)

## Attestations, at their real stage

Attestations at their real stage, not rounded up. This record changes when the stage does.

- **soc2.type2**: In progress. Auditor engaged.
- **fedramp**: Moderate path. Planned, not held.
- **cryptography**: FIPS 140-3 validated modules.
- **deployment**: GovCloud and GCC High available.

**Declared gap.** PolicyCortex holds no completed SOC 2 or FedRAMP attestation today: SOC 2 Type II is in progress and FedRAMP Moderate is planned. This page will say so when either changes.

## Six practices

Six practices, stated plainly. Each is checkable in a security review.

1. **Least privilege by default**: Cloud accounts onboarded with read-only scope; write scope per action class.
2. **Tamper-evident audit log**: Every platform action content-hashed; the chain is verifiable independent of PolicyCortex.
3. **No PHI, no CUI, no PII**: We process configuration metadata only. Cloud APIs return resource state, not data.
4. **SBOM, SAST, and DAST**: Continuous supply chain scanning. Dependency vulnerabilities tracked and patched.
5. **Annual penetration test**: Independent third-party penetration testing on the production platform.
6. **Incident response procedures**: Documented IR runbook. 24-hour notification SLA. Customer-facing security report.

## Questionnaires and disclosures

Have a security questionnaire (SIG-Lite, CAIQ, custom)? Email [security@policycortex.com](mailto:security@policycortex.com). We respond within one business day.

Vulnerability reports and data-processing questions follow the [disclosure policy](https://policycortex.com/disclosure).

Bring the questionnaire. We answer with the record. [Request Access](https://app.policycortex.com/auth?mode=request-access) · [Book a call](https://policycortex.com/book)

## Register colophon

| Seq | Label | SHA3-256 | Prev |
|---|---|---|---|
| REC 0000 | BOUNDARY | 84b2c2af10e1 | 0b3404a8c65c |
| REC 0001 | INTEGRITY | fa2aa4f7e1fa | 84b2c2af10e1 |
| REC 0002 | ATTESTATION STATUS | 5db17e8b2948 | fa2aa4f7e1fa |
| REC 0003 | PRACTICES | 62d8be706017 | 5db17e8b2948 |
| REC 0004 | CONTACT | 401e0752e0a1 | 62d8be706017 |

Head sha3:401e0752e0a17e911dea3dbba4c03b80e0c7840d6a69fe40b3779f34db5ce03c. Each digest is SHA3-256 over the previous digest, the register key, the record label, and the record copy; a second party can recompute it from this document.
