Skip to content
Foxx Cyberfoxxcyber/docs

Product Security Matrix

Which security model applies to which Foxx Cyber product — hosting, data sensitivity, compliance scope, and where to read the details.

Foxx Cyber products fall into three groups by hosting and data sensitivity. This page maps every product to its group, so you never have to assume the Bedrock SSP covers another product — or that a non-Bedrock product handles no sensitive data.

Draft — verify before publishing. The hosting, data-residency, and compliance-scope claims in the tables below were assembled from engineering knowledge and must be confirmed by the product owner before this page goes live. Security claims on a customer-facing page have to be exactly right. Anything you're unsure of should be softened or removed, not rounded up.

The models

Foxx Cyber products span three groups. Hosting and data sensitivity are separate axes — do not assume "not the Bedrock AWS platform" means "no sensitive data."

Bedrock CUI platformCommercial SaaSCompliance / GRC tools
ProductsBedrock CMMC, Bedrock C3PAOPraevio, RailCompliantBedrock RMF, Bedrock AFT
HostingAWS (dedicated)Railway (managed)Container — Railway or self-hosted, per deployment
Sensitive dataCUI, assessment evidenceHealth/fitness (incl. minors'), maintenance recordsCompliance artifacts that may contain CUI (RMF); classification metadata (AFT)
Compliance framingPublic summary of a NIST SP 800-171-aligned SSPCommercial SaaS practicesDeployment-governed; tool handles the customer's own compliance data
Payments—Stripe (no card data stored)—
Where to readBedrock SSPRailway-Hosted ProductsRailway-Hosted Products

Product-by-product

ProductGroupHostingWhat it handlesSecurity docs
Bedrock CMMCBedrock CUI platformAWSCUI, assessment evidenceBedrock SSP
Bedrock C3PAOBedrock CUI platformAWS (air-gapped assessor app)CUI, assessment recordsBedrock SSP
PraevioCommercial SaaSRailwayCoaching platform: health & fitness data, including minors'; payments via StripeRailway Products
RailCompliantCommercial SaaSRailwayFRA locomotive maintenance & compliance records; payments via StripeRailway Products
Bedrock RMFCompliance / GRC toolContainer (Railway or self-hosted)NIST RMF authorization artifacts (SSP, POA&M) + uploaded evidence — may contain CUI, governed by the deploymentRailway Products
Bedrock AFTCompliance / GRC toolContainer (Railway or self-hosted)Assured-file-transfer request records, approval/audit trail, and classification labels — not the transferred file contentsRailway Products

Bedrock RMF is not a "no-CUI" product. It manages RMF authorization packages — System Security Plans, POA&Ms, control implementations — and customer-uploaded evidence, which routinely contain Controlled Unclassified Information. Whether CUI is present, and what protects it, depends on the specific deployment and its controls. Do not describe RMF as free of CUI.

The Bedrock name spans all three groups. "Bedrock CMMC" and "Bedrock C3PAO" are the CUI-handling platform the SSP describes; "Bedrock RMF" and "Bedrock AFT" are compliance tools deployed as containers. Brand family and security model are different things — this table is the authority on which is which.

What every product shares

Regardless of model, every product in the table above is:

  • Built with VibeSecOps — the same rulebook, the same machine-enforced CI gates, the same human-in-the-loop verification.
  • Covered by one vulnerability disclosure process.
  • Operated with least-privilege access and encrypted transport. The specifics differ by model; the intent does not.

How to read the rest of this Trust Center

  • If your product is in the Bedrock platform row, the "Bedrock:" sections in the sidebar are written for you.
  • If your product is Railway-hosted, read Railway-Hosted Products — the Bedrock SSP sections describe infrastructure your product does not run on.
  • Everyone should read How We Build; it's the part that's true everywhere.

Last updated August 19, 2026