Where CUI Lives
The CUI boundary: what stays in your environment, what the platform stores, and why the assessor app is air-gapped.
If your organization handles Controlled Unclassified Information, the first question to ask any vendor is: does your product put my CUI in your cloud? Bedrock is deliberately architected so the answer is as narrow as possible.
The three boundaries
| Boundary | Who owns it | What lives there |
|---|---|---|
| Your environment (OSC) | You | Your CUI and evidence artifacts, under your own controls |
| Bedrock platform (Foxx Cyber's AWS) | Foxx Cyber | Your compliance working data — packages, control statuses, POA&Ms, asset records, SSP content, and files you choose to upload |
| Assessor environment (C3PAO) | The assessment firm | The assessment snapshot and findings, inside the assessor's own accredited boundary |
The assessor application is air-gapped
Bedrock C3PAO — the application assessors use to conduct assessments — runs entirely inside the assessor's own environment with its own local database. In the air-gapped deployment it makes no network calls to Foxx Cyber at all: no sync, no telemetry, no license phone-home.
Assessment data moves only by explicit, human-initiated file transfer:
- The OSC exports a snapshot package from their own boundary and delivers it to the C3PAO by the means the two parties agree on.
- The assessor imports it into the air-gapped application, conducts the assessment, and records findings locally.
- Results export back to the OSC the same way.
Foxx Cyber's cloud never sits in the assessment data path. For the assessment workflow, Foxx Cyber is a software vendor, not an External Service Provider — the CUI stays split between the OSC's boundary and the assessor's boundary, each covered by that party's own compliance scope.
Minimizing what the platform holds
The platform is designed around Security Protection Data (SPD) — statuses, metadata, and pointers — rather than warehousing CUI:
- Control implementation records, POA&Ms, and asset inventories are compliance metadata about your program.
- Evidence handling favors pointers to where evidence lives in your environment; the export assembles the actual package from your holdings at export time.
- Anything you do upload is encrypted at rest, tenant-isolated, and accessible only to your organization (see Encryption & Data Protection).
You control what you upload. If your CUI handling policy prohibits placing certain artifacts in a commercial cloud service, use evidence pointers instead of file uploads — the platform works either way.
For a user-level walkthrough of what moves where as you work, see How Your Data Flows (platform) and How Your Data Moves (assessor app).