Trust & Security
Security & Trust
Last reviewed: June 2026
Built to align with NIST SP 800-171 / CMMC Level 2 control objectives. Awardly is designed against the safeguarding objectives that matter to government contractors and their primes.
Architected to keep controlled documents outside your CUI boundary. Documents you analyze are parsed on your own device and are never uploaded to our servers — only the extracted text needed for the analysis leaves your machine. Running the AI analysis itself inside your own environment is on our roadmap (see below).
In plain terms: encrypted in transit and at rest; MFA supported; per-organization data isolation; a tamper-evident, independently verifiable audit trail; and controlled-information screening. The honest status of what is in place today versus what is on our roadmap is below — nothing on this page is a claim of compliance or certification.
Controls in place today
These protections are live in the product now:
- Encrypted in transit and at rest. All traffic is served over TLS; data at rest is encrypted by the underlying cloud platform.
- MFA supported. Multi-factor authentication (authenticator app + backup codes) is available on accounts.
- Per-organization data isolation. Records belonging to an organization carry a verified organization id, and every read and write is scoped server-side to the caller's organization — or, for accounts without one, to the account itself — derived from the RS256-verified token, never the request body, and backed by database indexes.
- Tamper-evident, independently verifiable audit trail. Security-relevant actions are written to an append-only, hash-chained audit log. It can be exported and re-verified independently — a verifier is available on request, so you don't have to take our word for it.
- Controlled-information screening. Documents are screened on your device for controlled markings, and saved entries are screened before storage. This is a best-effort safeguard, not a guarantee — automated screening cannot detect all controlled information, particularly unmarked or image-only content.
- Per-user controlled-information acknowledgment. Every user, at first use, must accept that Awardly is not authorized for CUI and that keeping it out is their responsibility — recorded to the tamper-evident audit log.
Controlled documents
When you analyze a document, it is parsed in your browser — only the extracted text needed for your analysis is processed, and the file itself never reaches our servers. Controlled markings detected on a document halt the analysis. Detection is best-effort and not guaranteed.
In place vs. roadmap
We keep this honest so you can make an informed decision.
In place today Now
- Encrypted in transit and at rest
- MFA supported
- Per-organization data isolation
- Tamper-evident, independently verifiable audit trail
- Controlled-information screening
- Per-user controlled-information acknowledgment (recorded to the audit log)
- On-device document parsing (files are never uploaded)
Roadmap & honest status Roadmap
- Not FedRAMP-authorized.
- Independent assessment (penetration testing, SOC 2) is on our roadmap.
- Bring-your-own-AI — on our roadmap: analysis running in your own environment, so the document and your AI key never reach our servers.
Standards
Built to align with NIST SP 800-171 / CMMC Level 2 control objectives. We map our controls to those objectives and design around them.
This is a statement of architectural alignment with those control objectives — not a claim of compliance or certification. Awardly is not FedRAMP-authorized, and independent assessment (penetration testing, SOC 2) is on our roadmap.