The Foxx Cyber Trust Center
One place to understand how we build our software securely and how each product is hosted and protected — because not every Foxx Cyber product carries the same security model.
Foxx Cyber builds more than one kind of software. Some of it is a compliance platform that handles Controlled Unclassified Information (CUI) on hardened AWS infrastructure. Some of it is commercial SaaS that runs on Railway and never touches CUI at all. Those are different security models, and this Trust Center is organized so you can tell which one applies to the product you actually use.
The single most common misunderstanding we want to prevent: the Bedrock System Security Plan — AWS GovCloud posture, CUI boundaries, the air-gapped C3PAO assessor application, NIST SP 800-171 control coverage — describes the Bedrock compliance platform only. It does not describe Praevio, RailCompliant, or our other Railway-hosted apps. Start with the Product Security Matrix to see what covers what.
What's in here
| Section | What it covers | Applies to |
|---|---|---|
| Trust Center (you are here) | Orientation + the product security matrix | Everything |
| How We Build (VibeSecOps) | Our AI-assisted development method and the machine-enforced rules that keep it disciplined | Every product we ship |
| Bedrock: Platform Overview / Controls / CUI / Responsibility Matrices | The public Bedrock System Security Plan | Bedrock platform only |
| Railway-Hosted Products | Hosting, data handling, authentication, and payments for our commercial SaaS | Praevio, RailCompliant, and other Railway apps |
| Policies & Disclosure | Vulnerability disclosure, subprocessors, data retention, support | Everything |
Two things every Foxx Cyber product shares
However a given product is hosted, two things are constant across the whole company:
- How it's built. Every product — CUI platform or commercial SaaS — is developed under the same method we call VibeSecOps: AI-assisted development constrained by explicit, written-down, machine-enforceable security rules, with a human who verifies and owns every change. The "vibe" is the speed. The "SecOps" is the discipline that catches mistakes before they ship.
- How to report a problem. One vulnerability disclosure process covers every product. If you find something, tell us and we'll act on it.
What this Trust Center is not
- It is not a contract or an SLA. Where a product has commitments in a signed agreement, that agreement governs.
- It is not the internal, full-granularity security documentation. The Bedrock pages here are a sanitized public summary of a much larger internal SSP; customers under agreement can request the full package through their point of contact.
- It does not rate one product's security as "better" than another's. A commercial SaaS app that never handles CUI should have a lighter model than a CUI platform. The point is to be precise about which model you're relying on, not to imply they should be identical.
Not sure which model applies to you? If you log in at a *.railway.app URL or
a product's own domain (for example railcompliant.com), you're almost
certainly on a Railway-hosted product.
If you're a CMMC assessor or an OSC working an assessment inside Bedrock,
you're on the Bedrock platform.