Security
Security for agents that can act.
Vulcan agents do real work on sensitive legal and government matters, with the access controls, human checkpoints, and audit trail your team is already required to maintain.

- SOC 2
- ISO 27001
- FedRAMP® Ready
- AWS GovCloud (US)
- TX-RAMP
Compliance & attestations
Independently audited, federally aligned.
Vulcan is built to the standards regulated and public-sector buyers require, and assessed by independent third parties. Reports and certificates are available to your team by request.
SOC 2
Independent audit of our security, availability, and confidentiality controls. Report available by request.
ISO 27001
Certified information security management system. Certificate available on request.
TX-RAMP
Aligned to Texas state agency security requirements for public-sector deployments.
FedRAMP & federal compliance
FedRAMP Ready, built to the full baseline.
VulcanGov, Vulcan's federal deployment, runs entirely in AWS GovCloud (US), inside an authorization boundary architected to the FedRAMP (Rev. 5) control baseline of roughly 325 controls across 17 families. An accredited third-party assessment organization (3PAO) independently assessed those controls, and VulcanGov is designated FedRAMP Ready and listed on the FedRAMP Marketplace as we pursue full authorization.
Continuous monitoring
AU · CA · SICloudTrail (multi-region, log-file validation), GuardDuty, AWS Security Hub on the FedRAMP standard, AWS Config, and VPC Flow Logs run across the GovCloud boundary. Wiz adds cloud security posture management, and Datadog provides observability and security monitoring.
Encryption everywhere
SCFIPS 140-2 validated cryptography, TLS in transit, and KMS-managed encryption at rest across databases, object storage, and logs, with keys rotated annually.
Identity & access
AC · IAOkta SAML SSO with MFA, role-based least privilege, and centralized identity across every account in the boundary.
Tamper-evident audit trail
AUA centralized, KMS-encrypted, versioned log store with object lock and multi-year retention. CloudWatch metric filters and alarms flag privileged and anomalous activity.
Configuration & change control
CMInfrastructure as code, automated configuration-compliance rules, and CI/CD guardrails that explicitly deny privilege escalation and security-service disruption.
Boundary & network protection
SC · SIIsolated GovCloud VPCs, private connectivity, network segmentation between tenants and environments, and centralized IP address management.
View VulcanGov on the FedRAMP Marketplace. The full control matrix, System Security Plan, and continuous-monitoring evidence are available to agencies and qualified prospects by request. Request a security briefing to review them with your team.
Data protection & privacy
Your data stays yours.
Customer data is encrypted, isolated, kept in the US, and never used to train AI models. You control retention, and sensitive material never leaves the deployment boundary.
Encryption everywhere
FIPS 140-2 validated cryptography protects data in transit (TLS) and at rest (KMS), with keys rotated annually.
Tenant isolation
Each deployment runs inside its own boundary. Customer data is segregated and never commingled across tenants.
US data residency
For federal customers, data is stored and processed entirely in AWS GovCloud (US), in us-gov-east-1.
No training on your data
Your documents and matter data are never used to train AI models. In the federal deployment, model inference runs through AWS Bedrock inside the GovCloud boundary.
Customer-controlled retention
You decide how long data is retained. On termination, customer data is removed from the environment.
Sensitive data stays inside
Privileged matter, citizen records, and pre-decisional materials never leave the deployment boundary.
Trust center
Everything your reviewers need.
Bring your security, legal, and procurement teams early. We can share documentation and walk through architecture, data boundaries, deployment posture, approval design, and audit evidence before a pilot starts.
SOC 2 report
Our most recent SOC 2 report, available by request.
FedRAMP control matrix & SSP
Control-by-control implementation detail for the GovCloud boundary.
Penetration test summary
An executive summary of our most recent third-party test.
Architecture & data-flow review
A walkthrough of boundaries, integrations, and where data lives.
