Defense-grade security posture, with the honest version of what's shipped.
Cincra protects the most sensitive compliance data in the DIB — including artifacts that document where CUI lives. We publish what's active, what's on the roadmap, and the line between them. No marketing claims dressed up as certifications.
Cincra is currently a pilot, not yet authorized for live CUI storage. Until the AWS GovCloud + FIPS migration completes, use representative or redacted artifacts only. This is the same disclosure surfaced to every user inside the platform.

What we do, what's coming, and how we tell them apart.
Commercial cloud today, GovCloud on the roadmap
Cincra runs on managed Postgres with Backblaze B2 private object storage in commercial-region infrastructure today. AWS GovCloud + FIPS-validated KMS is on our published roadmap before we accept live CUI. The data plane was deliberately built to swap without a rewrite.
TLS 1.2+ in transit. AES-256 at rest.
All traffic is TLS 1.2+ with HSTS. Data at rest is AES-256 via our cloud provider and B2 storage. FIPS 140-3-validated cryptographic modules arrive with the GovCloud migration — we do not claim FIPS validation today.
Row-Level Security at the database engine
Every domain row carries an org_id. Postgres RLS enforces tenant boundaries at the engine layer — not just in application code. Auditors only see engagements they were granted, scoped by token and expiry; cross-org access by MSP operators or Cincra staff is audit-logged.
MFA available. Recovery codes. Email + Google OAuth.
MFA enrollment is available to every account today and strongly recommended — mandatory MFA enforcement is on the near-term roadmap. Recovery codes are hashed and one-time. SAML/SSO and FIDO2 hardware keys are on the roadmap; we do not market features that are not shipped.
Hash-chained, tamper-evident logs
Every state-changing action writes to audit_logs with a cryptographic chain seal. Tampering anywhere in the chain is detectable at any later verification. The chain is available to authorized auditors via a read-only verification function.
Automated scans today. Third-party pen test before GA.
We run automated dependency and security scans on every release, and publish a security.txt for coordinated disclosure. A third-party penetration test is scheduled before we open General Availability — we do not currently claim annual pen-test results.
Security questions.
Read the full roadmap before you trust us with anything.
We publish every milestone — including the ones we haven't shipped — so you can decide for yourself whether Cincra is the right fit for your compliance posture today.