Trust Center
Current attestation status, plainly stated. We don't claim certifications we don't hold.
SOC 2-aligned
Not yet certifiedArchitecture and controls are designed to meet SOC 2 Trust Service Criteria. Fire Mission is not currently SOC 2 certified.
HIPAA-ready
ArchitectureTwo-plane isolation, AES-256 key encryption, and audit logging support BAA execution. Fire Mission is not currently HIPAA accredited.
NIST 800-53 alignment
Moderate baselineControl mapping covers the Moderate baseline. Not independently attested.
FedRAMP
Aligned, not authorizedArchitecture is FedRAMP-aligned. Fire Mission is not currently FedRAMP authorized.
PCI DSS SAQ-A
In placeCard data is tokenized via Stripe. Fire Mission never sees PAN bytes. Stripe enforces PCI DSS SAQ-A on our behalf.
GDPR / CCPA
In placeStandard Contractual Clauses for EU/EEA, GPC respected for California residents. Privacy policy at /legal#privacy.
Sub-processors
These third parties may process customer metadata or facilitate payments. We do not share AI prompt or completion bytes with anyone — queries pass through to your selected BYOK provider, or through our managed inference providers (Groq/Together AI) for platform-funded expert persona calls, and are never persisted.
| Sub-processor | Purpose | Region |
|---|---|---|
| Replit Deployments | Application hosting (US) | US |
| Replit Postgres | Control-plane metadata storage (US) | US |
| Stripe Payments | PCI SAQ-A card tokenization & subscription billing | US |
| Groq Cloud | Platform-funded managed AI inference for expert persona queries (Starter tier) | US |
| Together AI | Platform-funded managed AI inference for expert persona queries (Professional & Enterprise tiers) | US |
| Customer-supplied AI providers | BYOK passthrough — OpenAI, Anthropic, Google, Groq, Together AI, self-hosted | Per customer choice |
Data minimization
The least data you store is the least data that can be breached. Fire Mission is designed around this principle for document intelligence.
| Data type | Typical RAG platform | Fire Mission |
|---|---|---|
| Document content | Stored (chunks + full text) | Never stored — fetched ephemerally |
| Vector embeddings | Stored permanently in vector DB | Not generated or stored |
| Knowledge summaries | N/A (stores full chunks instead) | AI-generated metadata (~400 tokens/doc) |
| Query / prompt text | Often logged for model improvement | Never persisted — metadata only |
| Document pointers | Stored (alongside content) | Stored (title, path — no content) |
Knowledge summaries are model-generated distillations (not document excerpts) stored as metadata alongside the document pointer. Raw document bytes never enter the Fire Mission database at any point.
Security whitepaper
A plain-language summary of the Fire Mission threat model, two-plane isolation, security scanning pipeline, and incident response posture lives at /security. A formal whitepaper PDF is available on request for prospective Professional and Enterprise customers.
Request whitepaperCompliance language rule
We use precise wording everywhere on the public surface:
- "FedRAMP-aligned architecture" — never "FedRAMP certified" or "FedRAMP authorized".
- "HIPAA-ready" — never "HIPAA compliant".
- "SOC 2-aligned architecture" — never "SOC 2 certified".
- "NIST 800-53 aligned" — never "NIST 800-53 certified".
Report a vulnerability
Email mark@blackburntactical.us with subject "Security Vulnerability Report". We acknowledge within one business day. Coordinated disclosure preferred; no bounty program at this time.