Security & Trust

You're trusting Gray Warden with the data behind your compliance posture. Here's exactly how we protect it, and what we do not claim.

Access Control & Isolation

  • Role-based access control on every action
  • Granular control- and evidence-level access
  • Multi-factor authentication included on every plan, via authenticator app or email code, with backup codes
  • SAML 2.0 single sign-on with just-in-time provisioning

Encryption & Key Management

  • Data protected with FIPS 140-3 validated encryption, in transit and at rest (AES-256)
  • Keysafe (Enterprise, coming soon): your organization holds and manages its own encryption keys for data at rest
  • Refresh-token rotation on every session
  • Idle and absolute session timeouts enforced

Evidence & File Safety

  • Every uploaded file is scanned for malware before it's accepted
  • Files are streamed through the platform, with no public file URLs
  • Evidence expiration tracking flags stale artifacts

External Assessor Access

  • Assessors get read-only access scoped to a single engagement
  • MFA is enforced for every external auditor, regardless of tenant policy
  • Credentials expire automatically when the engagement ends
  • Every assessor action is captured in an access log

Audit & Accountability

  • Complete activity audit trail
  • IP address and user-agent captured per action
  • Searchable records for internal and external review

Methodology You Can Trust

  • Assessments built on NIST 800-171A / 800-53A objectives
  • SPRS scoring aligned to the DoD methodology
  • Curated, transparent cross-framework mapping library

Note: Gray Warden is a compliance management platform, not a certification body and not a legal advisor. Using Gray Warden does not guarantee CMMC certification. You remain responsible for your compliance program and should engage a qualified assessor for official certification.

Built Security-First for the DIB

Start your free trial, or talk to us about your specific security and data-residency requirements.