Skip to content
Foxx Cyberfoxxcyber/docs

How Your Data Flows

Where your compliance data lives, who can see it, and when it moves.

This page explains, from a user's point of view, what happens to your data as you work in Bedrock CMMC — where it's stored, who else can see it, and which actions share it outside your team.

Where your data lives

Everything you enter — packages, control statuses, POA&Ms, assets, SSP content, and service-provider records — is stored in your organization's own workspace on the Bedrock CMMC platform. Every record belongs to exactly one organization, and users only ever see the data of the organization they signed in to.

Evidence files you upload are stored in your organization's dedicated file storage. When you preview or download a file, the app fetches it through a short-lived secure link generated for that request.

Nothing you work on is stored on your computer; closing the browser only ends your session.

When changes are saved and seen

  • Saves are explicit. Forms and editors have a save action (Save objective, Create POA&M, Add asset, and so on). Until you click it, nothing is written.
  • Teammates see saved changes on their next load. Data refreshes when a page is opened or after a save; there is no live co-editing.
  • A few things poll automatically: the notification bell (about every 30 seconds), a running assessment snapshot (until it finishes), and an in-progress export job.

Who can see what

AudienceWhat they can seeHow access happens
Your teamEverything in your organization, subject to their role (Owner, Admin, User, Viewer, Consultant)Invited under Settings → Users & Roles
A guestOne package's compliance posture and its POA&Ms — never your implementation notes, evidence files, or other packagesInvited to a single package (MSP portal's Guest Access page); the grant can expire and can be revoked at any time
An RP partner firmThe specific packages your organization has granted, shown to them inside a workspace banner reading "Acting on behalf of your company"Granted per package; grants can carry an expiry date
Your C3PAO assessorOnly what you hand them yourself — see belowOut-of-band; the platform never transmits your package to an assessor

RP access is deliberately opaque in the other direction, too: an RP firm cannot even confirm the existence of an organization it hasn't been granted.

What leaves the platform

Three actions produce files that leave Bedrock CMMC, and all three are downloads you trigger yourself:

  1. Assessment snapshots — starting an assessment freezes the package at that moment into a bundle. You download it with Download snapshot bundle and deliver it to your C3PAO through your own channel. The platform never sends anything to the assessor.
  2. Excel export — the Export page produces a workbook of the package's own GRC data (controls, POA&Ms, assets, service providers, evidence index, SSP summary). Assessment determinations and vulnerability data are intentionally excluded.
  3. SSP documents — the SSP page's Export Word and Export PDF buttons generate document copies of your System Security Plan.

What is copied — and what never is

When an MSP clones a package, the system profile, control posture, and assets can be carried over, but evidence and POA&Ms are never copied — they are specific to the original package.

Last updated July 29, 2026