Security & Trust
You're trusting Gray Warden with the data behind your compliance posture. Here's exactly how we protect it, and what we do not claim.
Access Control & Isolation
- Role-based access control on every action
- Granular control- and evidence-level access
- Multi-factor authentication included on every plan, via authenticator app or email code, with backup codes
- SAML 2.0 single sign-on with just-in-time provisioning
Encryption & Key Management
- Data protected with FIPS 140-3 validated encryption, in transit and at rest (AES-256)
- Keysafe (Enterprise, coming soon): your organization holds and manages its own encryption keys for data at rest
- Refresh-token rotation on every session
- Idle and absolute session timeouts enforced
Evidence & File Safety
- Every uploaded file is scanned for malware before it's accepted
- Files are streamed through the platform, with no public file URLs
- Evidence expiration tracking flags stale artifacts
External Assessor Access
- Assessors get read-only access scoped to a single engagement
- MFA is enforced for every external auditor, regardless of tenant policy
- Credentials expire automatically when the engagement ends
- Every assessor action is captured in an access log
Audit & Accountability
- Complete activity audit trail
- IP address and user-agent captured per action
- Searchable records for internal and external review
Methodology You Can Trust
- Assessments built on NIST 800-171A / 800-53A objectives
- SPRS scoring aligned to the DoD methodology
- Curated, transparent cross-framework mapping library
Note: Gray Warden is a compliance management platform, not a certification body and not a legal advisor. Using Gray Warden does not guarantee CMMC certification. You remain responsible for your compliance program and should engage a qualified assessor for official certification.
Built Security-First for the DIB
Start your free trial, or talk to us about your specific security and data-residency requirements.