Security & compliance
Iron Brick APIs are designed to run inside the agency's authorization boundary and inherit its controls. The sandbox is a public demonstration environment with synthetic data only; it is not FedRAMP authorized and must not receive real personal information.
| Area | Approach in agency deployments |
|---|---|
| Hosting | Agency FedRAMP-authorized cloud (for example AWS GovCloud, Azure Government) or on premises |
| Identity | Agency IdP, PIV/CAC for staff, least-privilege scopes, short-lived tokens |
| Controls | Designed to support NIST SP 800-53 Rev. 5 control families (AC, AU, IA, SC, SI) and zero trust principles (OMB M-22-09) |
| Encryption | TLS 1.2+ with FIPS 140-validated modules in transit; agency key management at rest |
| Audit | Every call logged with actor, on-behalf-of user, resource, and outcome; export to Splunk or other SIEM |
| Privacy | Field-level masking, data minimization, support for Privacy Act and PIA requirements |
| Accessibility | Portal pages built to WCAG 2.1 AA / Section 508 |
| AI | Human approval for writes, citations, and use-case inventory support aligned to OMB AI guidance |
Reporting a vulnerability
Email info@ironbrick.us with "Security" in the subject. Please do not test against systems you do not own; the sandbox may be tested within its rate limits.