Compliance & Security Standards
Data Residency
All data processed and stored by MAS Pilot resides within the United States. We do not transfer contractor data outside the United States. Our infrastructure is hosted on US-based cloud services.
NIST SP 800-171
MAS Pilot is designed with reference to the security controls outlined in NIST Special Publication 800-171, Protecting Controlled Unclassified Information in Nonfederal Systems and Organizations. Key controls in our security design include (some are targeted for general availability rather than live today — see our Security page for current status):
- Access Control (3.1) — Role-based access, least privilege, session management, and MFA for administrative access
- Audit and Accountability (3.3) — Comprehensive audit logging of all user and system actions
- Configuration Management (3.4) — Baseline configurations and change management for all systems
- Identification and Authentication (3.5) — Unique user accounts, strong password requirements, and MFA
- Incident Response (3.6) — Documented incident response procedures and breach notification processes
- System and Communications Protection (3.13) — Encryption in transit (TLS 1.3) and at rest (AES-256)
MAS Pilot does not process, store, or transmit Controlled Unclassified Information (CUI) on behalf of the government. Our platform processes contractor-originated data only.
FAR 52.204-21 — Basic Safeguarding
MAS Pilot implements the basic safeguarding requirements for contractor information systems as required by FAR 52.204-21. These include limiting system access to authorized users, using encryption for transmitting covered contractor information, and protecting information consistent with FAR requirements.
Section 508 / WCAG 2.1
We are committed to Section 508 compliance and WCAG 2.1 Level AA conformance. See our Accessibility Statement for current status and known limitations.
FedRAMP
MAS Pilot is not FedRAMP authorized. FedRAMP authorization applies to a specific system boundary and is not inherited by a product simply because it runs on an authorized cloud provider. Achieving FedRAMP High — via a planned GCP-based deployment — is on our roadmap, not our present state. If your program office has specific FedRAMP requirements, please contact us to discuss timing and applicability.
Encryption
- In transit: All communications between your browser and MAS Pilot are encrypted using TLS 1.3. We do not support TLS 1.0 or 1.1.
- At rest: Data stored in our managed database is encrypted at rest using provider-managed AES-256 encryption.
- Transactional data (target design — pre-launch): Pricing and sales data submitted for TDR checking is designed to be processed in-memory only and not written to persistent storage. Independent attestation of this design (SOC 2 Type II) is planned before general availability; enterprise evaluators may request current readiness status under NDA.
Vulnerability Disclosure
We operate a responsible disclosure policy. If you discover a security vulnerability in MAS Pilot, please report it to [email protected] with the subject line "Security Disclosure" before public disclosure. We commit to responding within 3 business days and resolving confirmed vulnerabilities within 30 days.
Penetration Testing
MAS Pilot is pre-launch and is working toward SOC 2 Type II attestation and annual third-party penetration testing before general availability. If you are evaluating MAS Pilot for an enterprise pilot, or are a government agency conducting vendor due diligence, current security documentation and readiness status are available under NDA upon written request.
Business Continuity
MAS Pilot maintains a documented business continuity and disaster recovery plan with Recovery Time Objective (RTO) and Recovery Point Objective (RPO) targets appropriate for a business-critical SaaS platform.
Contact
For security and compliance inquiries: [email protected]
Subject: Security / Compliance Inquiry