Product Security Matrix
Which security model applies to which Foxx Cyber product — hosting, data sensitivity, compliance scope, and where to read the details.
Foxx Cyber products fall into three groups by hosting and data sensitivity. This page maps every product to its group, so you never have to assume the Bedrock SSP covers another product — or that a non-Bedrock product handles no sensitive data.
Draft — verify before publishing. The hosting, data-residency, and compliance-scope claims in the tables below were assembled from engineering knowledge and must be confirmed by the product owner before this page goes live. Security claims on a customer-facing page have to be exactly right. Anything you're unsure of should be softened or removed, not rounded up.
The models
Foxx Cyber products span three groups. Hosting and data sensitivity are separate axes — do not assume "not the Bedrock AWS platform" means "no sensitive data."
| Bedrock CUI platform | Commercial SaaS | Compliance / GRC tools | |
|---|---|---|---|
| Products | Bedrock CMMC, Bedrock C3PAO | Praevio, RailCompliant | Bedrock RMF, Bedrock AFT |
| Hosting | AWS (dedicated) | Railway (managed) | Container — Railway or self-hosted, per deployment |
| Sensitive data | CUI, assessment evidence | Health/fitness (incl. minors'), maintenance records | Compliance artifacts that may contain CUI (RMF); classification metadata (AFT) |
| Compliance framing | Public summary of a NIST SP 800-171-aligned SSP | Commercial SaaS practices | Deployment-governed; tool handles the customer's own compliance data |
| Payments | — | Stripe (no card data stored) | — |
| Where to read | Bedrock SSP | Railway-Hosted Products | Railway-Hosted Products |
Product-by-product
| Product | Group | Hosting | What it handles | Security docs |
|---|---|---|---|---|
| Bedrock CMMC | Bedrock CUI platform | AWS | CUI, assessment evidence | Bedrock SSP |
| Bedrock C3PAO | Bedrock CUI platform | AWS (air-gapped assessor app) | CUI, assessment records | Bedrock SSP |
| Praevio | Commercial SaaS | Railway | Coaching platform: health & fitness data, including minors'; payments via Stripe | Railway Products |
| RailCompliant | Commercial SaaS | Railway | FRA locomotive maintenance & compliance records; payments via Stripe | Railway Products |
| Bedrock RMF | Compliance / GRC tool | Container (Railway or self-hosted) | NIST RMF authorization artifacts (SSP, POA&M) + uploaded evidence — may contain CUI, governed by the deployment | Railway Products |
| Bedrock AFT | Compliance / GRC tool | Container (Railway or self-hosted) | Assured-file-transfer request records, approval/audit trail, and classification labels — not the transferred file contents | Railway Products |
Bedrock RMF is not a "no-CUI" product. It manages RMF authorization packages — System Security Plans, POA&Ms, control implementations — and customer-uploaded evidence, which routinely contain Controlled Unclassified Information. Whether CUI is present, and what protects it, depends on the specific deployment and its controls. Do not describe RMF as free of CUI.
The Bedrock name spans all three groups. "Bedrock CMMC" and "Bedrock C3PAO" are the CUI-handling platform the SSP describes; "Bedrock RMF" and "Bedrock AFT" are compliance tools deployed as containers. Brand family and security model are different things — this table is the authority on which is which.
What every product shares
Regardless of model, every product in the table above is:
- Built with VibeSecOps — the same rulebook, the same machine-enforced CI gates, the same human-in-the-loop verification.
- Covered by one vulnerability disclosure process.
- Operated with least-privilege access and encrypted transport. The specifics differ by model; the intent does not.
How to read the rest of this Trust Center
- If your product is in the Bedrock platform row, the "Bedrock:" sections in the sidebar are written for you.
- If your product is Railway-hosted, read Railway-Hosted Products — the Bedrock SSP sections describe infrastructure your product does not run on.
- Everyone should read How We Build; it's the part that's true everywhere.