About This Document
What this public System Security Plan covers, what it deliberately leaves out, and how to request more.
This section is the public version of the Bedrock System Security Plan (SSP) — a plain-language summary of how Foxx Cyber LLC secures the Bedrock platform: the web application, the backend API, the AWS infrastructure they run on, and the air-gapped C3PAO assessor application.
It exists so that prospective customers, partners, and assessors can evaluate Bedrock's security posture without an NDA or a sales call.
What's covered
- System description — the components that make up Bedrock and where the system boundary sits.
- Shared responsibility — which controls come from AWS, which Foxx Cyber implements, and which remain with you as the customer.
- Platform security controls — identity and access, encryption, network architecture, logging and monitoring, change management, and vulnerability and incident management, organized along NIST SP 800-171 domain lines.
- CUI handling — where Controlled Unclassified Information does and does not travel, including the air-gapped assessment model.
What's deliberately left out
This is a sanitized summary. The internal SSP is maintained at assessment-objective granularity (every NIST SP 800-171A determination statement, with implementation evidence). The public version omits:
- Internal identifiers — account numbers, resource names, network addresses, and topology diagrams.
- Plan of Action & Milestones (POA&M) content and remediation timelines.
- Evidence artifacts and internal procedure documents.
Customers and partners with a signed agreement can request the full SSP, Customer Responsibility Matrix, and supporting documentation through their Foxx Cyber point of contact or a support ticket.
Accuracy and maintenance
This summary is derived from the internal Bedrock SSP and is updated when the underlying plan materially changes. Statements here are written to be verifiable — where a capability is optional (for example, multi-factor authentication) or in progress, we say so rather than round up.