Trust Center

Current attestation status, plainly stated. We don't claim certifications we don't hold.

SOC 2-aligned

Not yet certified

Architecture and controls are designed to meet SOC 2 Trust Service Criteria. Fire Mission is not currently SOC 2 certified.

HIPAA-ready

Architecture

Two-plane isolation, AES-256 key encryption, and audit logging support BAA execution. Fire Mission is not currently HIPAA accredited.

NIST 800-53 alignment

Moderate baseline

Control mapping covers the Moderate baseline. Not independently attested.

FedRAMP

Aligned, not authorized

Architecture is FedRAMP-aligned. Fire Mission is not currently FedRAMP authorized.

PCI DSS SAQ-A

In place

Card data is tokenized via Stripe. Fire Mission never sees PAN bytes. Stripe enforces PCI DSS SAQ-A on our behalf.

GDPR / CCPA

In place

Standard Contractual Clauses for EU/EEA, GPC respected for California residents. Privacy policy at /legal#privacy.

Sub-processors

These third parties may process customer metadata or facilitate payments. We do not share AI prompt or completion bytes with anyone — queries pass through to your selected BYOK provider, or through our managed inference providers (Groq/Together AI) for platform-funded expert persona calls, and are never persisted.

Sub-processorPurposeRegion
Replit DeploymentsApplication hosting (US)US
Replit PostgresControl-plane metadata storage (US)US
Stripe PaymentsPCI SAQ-A card tokenization & subscription billingUS
Groq CloudPlatform-funded managed AI inference for expert persona queries (Starter tier)US
Together AIPlatform-funded managed AI inference for expert persona queries (Professional & Enterprise tiers)US
Customer-supplied AI providersBYOK passthrough — OpenAI, Anthropic, Google, Groq, Together AI, self-hostedPer customer choice

Data minimization

The least data you store is the least data that can be breached. Fire Mission is designed around this principle for document intelligence.

Data typeTypical RAG platformFire Mission
Document contentStored (chunks + full text)Never stored — fetched ephemerally
Vector embeddingsStored permanently in vector DBNot generated or stored
Knowledge summariesN/A (stores full chunks instead)AI-generated metadata (~400 tokens/doc)
Query / prompt textOften logged for model improvementNever persisted — metadata only
Document pointersStored (alongside content)Stored (title, path — no content)

Knowledge summaries are model-generated distillations (not document excerpts) stored as metadata alongside the document pointer. Raw document bytes never enter the Fire Mission database at any point.

Security whitepaper

A plain-language summary of the Fire Mission threat model, two-plane isolation, security scanning pipeline, and incident response posture lives at /security. A formal whitepaper PDF is available on request for prospective Professional and Enterprise customers.

Request whitepaper

Compliance language rule

We use precise wording everywhere on the public surface:

  • "FedRAMP-aligned architecture" — never "FedRAMP certified" or "FedRAMP authorized".
  • "HIPAA-ready" — never "HIPAA compliant".
  • "SOC 2-aligned architecture" — never "SOC 2 certified".
  • "NIST 800-53 aligned" — never "NIST 800-53 certified".

Report a vulnerability

Email mark@blackburntactical.us with subject "Security Vulnerability Report". We acknowledge within one business day. Coordinated disclosure preferred; no bounty program at this time.