How Your Data Flows
Where your compliance data lives, who can see it, and when it moves.
This page explains, from a user's point of view, what happens to your data as you work in Bedrock CMMC — where it's stored, who else can see it, and which actions share it outside your team.
Where your data lives
Everything you enter — packages, control statuses, POA&Ms, assets, SSP content, and service-provider records — is stored in your organization's own workspace on the Bedrock CMMC platform. Every record belongs to exactly one organization, and users only ever see the data of the organization they signed in to.
Evidence files you upload are stored in your organization's dedicated file storage. When you preview or download a file, the app fetches it through a short-lived secure link generated for that request.
Nothing you work on is stored on your computer; closing the browser only ends your session.
When changes are saved and seen
- Saves are explicit. Forms and editors have a save action (Save objective, Create POA&M, Add asset, and so on). Until you click it, nothing is written.
- Teammates see saved changes on their next load. Data refreshes when a page is opened or after a save; there is no live co-editing.
- A few things poll automatically: the notification bell (about every 30 seconds), a running assessment snapshot (until it finishes), and an in-progress export job.
Who can see what
| Audience | What they can see | How access happens |
|---|---|---|
| Your team | Everything in your organization, subject to their role (Owner, Admin, User, Viewer, Consultant) | Invited under Settings → Users & Roles |
| A guest | One package's compliance posture and its POA&Ms — never your implementation notes, evidence files, or other packages | Invited to a single package (MSP portal's Guest Access page); the grant can expire and can be revoked at any time |
| An RP partner firm | The specific packages your organization has granted, shown to them inside a workspace banner reading "Acting on behalf of your company" | Granted per package; grants can carry an expiry date |
| Your C3PAO assessor | Only what you hand them yourself — see below | Out-of-band; the platform never transmits your package to an assessor |
RP access is deliberately opaque in the other direction, too: an RP firm cannot even confirm the existence of an organization it hasn't been granted.
What leaves the platform
Three actions produce files that leave Bedrock CMMC, and all three are downloads you trigger yourself:
- Assessment snapshots — starting an assessment freezes the package at that moment into a bundle. You download it with Download snapshot bundle and deliver it to your C3PAO through your own channel. The platform never sends anything to the assessor.
- Excel export — the Export page produces a workbook of the package's own GRC data (controls, POA&Ms, assets, service providers, evidence index, SSP summary). Assessment determinations and vulnerability data are intentionally excluded.
- SSP documents — the SSP page's Export Word and Export PDF buttons generate document copies of your System Security Plan.
What is copied — and what never is
When an MSP clones a package, the system profile, control posture, and assets can be carried over, but evidence and POA&Ms are never copied — they are specific to the original package.