Deadline

Nov 2026: DoD CMMC L2 enforcement begins for new prime contracts. Most DIB firms aren't ready. See your gap →

Trust & Security

Defense-grade security posture, with the honest version of what's shipped.

Cincra protects the most sensitive compliance data in the DIB — including artifacts that document where CUI lives. We publish what's active, what's on the roadmap, and the line between them. No marketing claims dressed up as certifications.

Pilot status — read this first

Cincra is currently a pilot, not yet authorized for live CUI storage. Until the AWS GovCloud + FIPS migration completes, use representative or redacted artifacts only. This is the same disclosure surfaced to every user inside the platform.

Cincra security pillars: RLS tenant isolation, hash-chained audit logs, TLS 1.2+, MFA available
Tenant-isolated · Hash-chained audit · MFA available (mandatory on roadmap)
Six security pillars

What we do, what's coming, and how we tell them apart.

Hosting & infrastructure

Commercial cloud today, GovCloud on the roadmap

Cincra runs on managed Postgres with Backblaze B2 private object storage in commercial-region infrastructure today. AWS GovCloud + FIPS-validated KMS is on our published roadmap before we accept live CUI. The data plane was deliberately built to swap without a rewrite.

Pilot: commercial cloud · Roadmap: AWS GovCloud + FIPS
Encryption

TLS 1.2+ in transit. AES-256 at rest.

All traffic is TLS 1.2+ with HSTS. Data at rest is AES-256 via our cloud provider and B2 storage. FIPS 140-3-validated cryptographic modules arrive with the GovCloud migration — we do not claim FIPS validation today.

Active today
Tenant isolation

Row-Level Security at the database engine

Every domain row carries an org_id. Postgres RLS enforces tenant boundaries at the engine layer — not just in application code. Auditors only see engagements they were granted, scoped by token and expiry; cross-org access by MSP operators or Cincra staff is audit-logged.

Active today
Authentication

MFA available. Recovery codes. Email + Google OAuth.

MFA enrollment is available to every account today and strongly recommended — mandatory MFA enforcement is on the near-term roadmap. Recovery codes are hashed and one-time. SAML/SSO and FIDO2 hardware keys are on the roadmap; we do not market features that are not shipped.

MFA available · mandatory enforcement on roadmap
Audit trail

Hash-chained, tamper-evident logs

Every state-changing action writes to audit_logs with a cryptographic chain seal. Tampering anywhere in the chain is detectable at any later verification. The chain is available to authorized auditors via a read-only verification function.

Active today
Vulnerability management

Automated scans today. Third-party pen test before GA.

We run automated dependency and security scans on every release, and publish a security.txt for coordinated disclosure. A third-party penetration test is scheduled before we open General Availability — we do not currently claim annual pen-test results.

Automated scans active · Pen test scheduled pre-GA
Frequently asked

Security questions.

No. Cincra is a pilot environment on commercial cloud — not FedRAMP, not FIPS, not GovCloud. Use representative or redacted artifacts only until the GovCloud migration completes. This is the same disclosure shown to every user inside the platform.

Read the full roadmap before you trust us with anything.

We publish every milestone — including the ones we haven't shipped — so you can decide for yourself whether Cincra is the right fit for your compliance posture today.