Vulcan agents do real work on sensitive legal and government matters, with the access controls, human checkpoints, and audit trail your team is already required to maintain.
Compliance & attestations
Vulcan is built to the standards regulated and public-sector buyers require, and assessed by independent third parties. Reports and certificates are available to your team by request.
Independent audit of our security, availability, and confidentiality controls. Report available by request.
Certified information security management system. Certificate available on request.
Aligned to Texas state agency security requirements for public-sector deployments.
FedRAMP & federal compliance
VulcanGov, Vulcan's federal deployment, runs entirely in AWS GovCloud (US), inside an authorization boundary architected to the FedRAMP (Rev. 5) control baseline of roughly 325 controls across 17 families. An accredited third-party assessment organization (3PAO) independently assessed those controls, and VulcanGov is designated FedRAMP Ready and listed on the FedRAMP Marketplace as we pursue full authorization.
CloudTrail (multi-region, log-file validation), GuardDuty, AWS Security Hub on the FedRAMP standard, AWS Config, and VPC Flow Logs run across the GovCloud boundary. Wiz adds cloud security posture management, and Datadog provides observability and security monitoring.
FIPS 140-2 validated cryptography, TLS in transit, and KMS-managed encryption at rest across databases, object storage, and logs, with keys rotated annually.
Okta SAML SSO with MFA, role-based least privilege, and centralized identity across every account in the boundary.
A centralized, KMS-encrypted, versioned log store with object lock and multi-year retention. CloudWatch metric filters and alarms flag privileged and anomalous activity.
Infrastructure as code, automated configuration-compliance rules, and CI/CD guardrails that explicitly deny privilege escalation and security-service disruption.
Isolated GovCloud VPCs, private connectivity, network segmentation between tenants and environments, and centralized IP address management.
View VulcanGov on the FedRAMP Marketplace. The full control matrix, System Security Plan, and continuous-monitoring evidence are available to agencies and qualified prospects by request. Request a security briefing to review them with your team.
Data protection & privacy
Customer data is encrypted, isolated, kept in the US, and never used to train AI models. You control retention, and sensitive material never leaves the deployment boundary.
FIPS 140-2 validated cryptography protects data in transit (TLS) and at rest (KMS), with keys rotated annually.
Each deployment runs inside its own boundary. Customer data is segregated and never commingled across tenants.
For federal customers, data is stored and processed entirely in AWS GovCloud (US), in us-gov-east-1.
Your documents and matter data are never used to train AI models. In the federal deployment, model inference runs through AWS Bedrock inside the GovCloud boundary.
You decide how long data is retained. On termination, customer data is removed from the environment.
Privileged matter, citizen records, and pre-decisional materials never leave the deployment boundary.
Trust center
Bring your security, legal, and procurement teams early. We can share documentation and walk through architecture, data boundaries, deployment posture, approval design, and audit evidence before a pilot starts.
Our most recent SOC 2 report, available by request.
Control-by-control implementation detail for the GovCloud boundary.
An executive summary of our most recent third-party test.
A walkthrough of boundaries, integrations, and where data lives.