Skip to content
Foxx Cyberfoxxcyber/docs

Shared Responsibility

Which security controls come from AWS, which Foxx Cyber implements, and which stay with you.

Bedrock's security posture is built in three layers. Understanding the split matters when you scope your own compliance program: some NIST SP 800-171 practices are satisfied by the platform's infrastructure provider, some by Foxx Cyber, and some can only ever be satisfied by your organization.

AWS — physical and infrastructure controls

The platform runs exclusively in AWS, so the physical and low-level infrastructure controls are inherited from AWS's FedRAMP-authorized environment:

  • Data center physical security, visitor control, and physical access logging
  • Hardware maintenance and maintenance-personnel supervision
  • Storage media protection, sanitization (NIST 800-88), and disposal
  • Environmental controls, network infrastructure, and hypervisor isolation
  • Wireless security (Foxx Cyber operates no wireless infrastructure)

Foxx Cyber — application and configuration controls

Everything from the operating environment configuration up through the application is Foxx Cyber's responsibility:

  • Application layer — authentication and role-based authorization, session management, tenant isolation, input validation, application-level audit logging, and secure password storage.
  • AWS configuration — least-privilege IAM roles, network segmentation and security-group rules, encryption key management, storage policies, web application firewall rules, container image security, and the logging/monitoring/threat-detection stack.
  • Organizational controls — risk assessment, incident response, personnel security, and maintenance of the System Security Plan itself.

You — your data and your users

No SaaS platform can take these off your plate:

  • Account hygiene — who in your organization gets an account, their role assignments, enabling MFA on your accounts, and removing users when people leave.
  • What you upload — Bedrock gives you an encrypted place to work, but you decide what goes into it. Follow your own CUI handling policy when deciding what to store; see Where CUI Lives.
  • Your endpoints — the laptops and browsers your team uses to reach Bedrock, and any mobile-device or portable-storage policies your program requires.

This page is the narrative version. For the control-by-control view — and how to cite it in your own assessment — see the Shared Responsibility Matrix and Customer Responsibility Matrix pages, and Bedrock as Your ESP for documenting Foxx Cyber in your SSP.

Last updated July 29, 2026