Skip to content
Foxx Cyberfoxxcyber/docs

Where CUI Lives

The CUI boundary: what stays in your environment, what the platform stores, and why the assessor app is air-gapped.

If your organization handles Controlled Unclassified Information, the first question to ask any vendor is: does your product put my CUI in your cloud? Bedrock is deliberately architected so the answer is as narrow as possible.

The three boundaries

BoundaryWho owns itWhat lives there
Your environment (OSC)YouYour CUI and evidence artifacts, under your own controls
Bedrock platform (Foxx Cyber's AWS)Foxx CyberYour compliance working data — packages, control statuses, POA&Ms, asset records, SSP content, and files you choose to upload
Assessor environment (C3PAO)The assessment firmThe assessment snapshot and findings, inside the assessor's own accredited boundary

The assessor application is air-gapped

Bedrock C3PAO — the application assessors use to conduct assessments — runs entirely inside the assessor's own environment with its own local database. In the air-gapped deployment it makes no network calls to Foxx Cyber at all: no sync, no telemetry, no license phone-home.

Assessment data moves only by explicit, human-initiated file transfer:

  1. The OSC exports a snapshot package from their own boundary and delivers it to the C3PAO by the means the two parties agree on.
  2. The assessor imports it into the air-gapped application, conducts the assessment, and records findings locally.
  3. Results export back to the OSC the same way.

Foxx Cyber's cloud never sits in the assessment data path. For the assessment workflow, Foxx Cyber is a software vendor, not an External Service Provider — the CUI stays split between the OSC's boundary and the assessor's boundary, each covered by that party's own compliance scope.

Minimizing what the platform holds

The platform is designed around Security Protection Data (SPD) — statuses, metadata, and pointers — rather than warehousing CUI:

  • Control implementation records, POA&Ms, and asset inventories are compliance metadata about your program.
  • Evidence handling favors pointers to where evidence lives in your environment; the export assembles the actual package from your holdings at export time.
  • Anything you do upload is encrypted at rest, tenant-isolated, and accessible only to your organization (see Encryption & Data Protection).

You control what you upload. If your CUI handling policy prohibits placing certain artifacts in a commercial cloud service, use evidence pointers instead of file uploads — the platform works either way.

For a user-level walkthrough of what moves where as you work, see How Your Data Flows (platform) and How Your Data Moves (assessor app).

Last updated July 29, 2026