Security at Responder
Last updated [date]
Proposals carry some of a contractor's most sensitive information, often including CUI. Responder is built to keep that data inside the government boundary, visible only to the people who need it, with every access recorded. This beta runs in commercial AWS until the move to AWS GovCloud (US), so it doesn't accept CUI or export-controlled data yet.
1. Hosting
- Runs entirely in AWS US regions: application, database, file storage, queues and email. Operated by US persons.
- AI runs through Amazon Bedrock in US regions. Your data isn't stored by the model provider or used to train models.
- Payments go through Stripe, which receives billing details and usage counts only, never proposal content.
2. Encryption and isolation
- Every organization has its own AWS KMS key; its files are encrypted with it at rest.
- Organizations are separated by database row-level security, enforced by Postgres itself, not just application code.
- TLS 1.2+ in transit, with HSTS.
3. Access control
- Multi-factor authentication is required for every account.
- Role-based permissions, need-to-know (restricted) teams, separate price access, and time-limited partner guests who see only the folders shared with them.
- Sessions end after 30 minutes of inactivity.
4. Audit and monitoring
- An append-only audit log of access and changes, which admins can review and export.
- Centralized logging and alerting; logs never contain proposal content.
- Web application firewall and rate limiting in front of the service.
5. Resilience
- In production, a Multi-AZ database with point-in-time recovery.
- Versioned file storage and tested restores.
6. Compliance roadmap
We follow NIST SP 800-171 and are working toward CMMC Level 2. [Update with facts as they happen: SPRS score submitted, SOC 2 Type II report available under NDA, CMMC assessment date.] Ask us for our System Security Plan and shared-responsibility matrix.
7. Reporting a vulnerability
Email [security@…]. We respond within two business days.