Skip to main content

Security & compliance

Iron Brick APIs are designed to run inside the agency's authorization boundary and inherit its controls. The sandbox is a public demonstration environment with synthetic data only; it is not FedRAMP authorized and must not receive real personal information.

AreaApproach in agency deployments
HostingAgency FedRAMP-authorized cloud (for example AWS GovCloud, Azure Government) or on premises
IdentityAgency IdP, PIV/CAC for staff, least-privilege scopes, short-lived tokens
ControlsDesigned to support NIST SP 800-53 Rev. 5 control families (AC, AU, IA, SC, SI) and zero trust principles (OMB M-22-09)
EncryptionTLS 1.2+ with FIPS 140-validated modules in transit; agency key management at rest
AuditEvery call logged with actor, on-behalf-of user, resource, and outcome; export to Splunk or other SIEM
PrivacyField-level masking, data minimization, support for Privacy Act and PIA requirements
AccessibilityPortal pages built to WCAG 2.1 AA / Section 508
AIHuman approval for writes, citations, and use-case inventory support aligned to OMB AI guidance

Reporting a vulnerability

Email info@ironbrick.us with "Security" in the subject. Please do not test against systems you do not own; the sandbox may be tested within its rate limits.