Skip to content
Foxx Cyberfoxxcyber/docs

The Foxx Cyber Trust Center

One place to understand how we build our software securely and how each product is hosted and protected — because not every Foxx Cyber product carries the same security model.

Foxx Cyber builds more than one kind of software. Some of it is a compliance platform that handles Controlled Unclassified Information (CUI) on hardened AWS infrastructure. Some of it is commercial SaaS that runs on Railway and never touches CUI at all. Those are different security models, and this Trust Center is organized so you can tell which one applies to the product you actually use.

The single most common misunderstanding we want to prevent: the Bedrock System Security Plan — AWS GovCloud posture, CUI boundaries, the air-gapped C3PAO assessor application, NIST SP 800-171 control coverage — describes the Bedrock compliance platform only. It does not describe Praevio, RailCompliant, or our other Railway-hosted apps. Start with the Product Security Matrix to see what covers what.

What's in here

SectionWhat it coversApplies to
Trust Center (you are here)Orientation + the product security matrixEverything
How We Build (VibeSecOps)Our AI-assisted development method and the machine-enforced rules that keep it disciplinedEvery product we ship
Bedrock: Platform Overview / Controls / CUI / Responsibility MatricesThe public Bedrock System Security PlanBedrock platform only
Railway-Hosted ProductsHosting, data handling, authentication, and payments for our commercial SaaSPraevio, RailCompliant, and other Railway apps
Policies & DisclosureVulnerability disclosure, subprocessors, data retention, supportEverything

Two things every Foxx Cyber product shares

However a given product is hosted, two things are constant across the whole company:

  1. How it's built. Every product — CUI platform or commercial SaaS — is developed under the same method we call VibeSecOps: AI-assisted development constrained by explicit, written-down, machine-enforceable security rules, with a human who verifies and owns every change. The "vibe" is the speed. The "SecOps" is the discipline that catches mistakes before they ship.
  2. How to report a problem. One vulnerability disclosure process covers every product. If you find something, tell us and we'll act on it.

What this Trust Center is not

  • It is not a contract or an SLA. Where a product has commitments in a signed agreement, that agreement governs.
  • It is not the internal, full-granularity security documentation. The Bedrock pages here are a sanitized public summary of a much larger internal SSP; customers under agreement can request the full package through their point of contact.
  • It does not rate one product's security as "better" than another's. A commercial SaaS app that never handles CUI should have a lighter model than a CUI platform. The point is to be precise about which model you're relying on, not to imply they should be identical.

Not sure which model applies to you? If you log in at a *.railway.app URL or a product's own domain (for example railcompliant.com), you're almost certainly on a Railway-hosted product. If you're a CMMC assessor or an OSC working an assessment inside Bedrock, you're on the Bedrock platform.

Last updated August 19, 2026