Governance operating model
In placeGovernance-first is a stated operating principle, not a marketing line: named policy packs, human approval gates on sensitive actions, and hash-chained audit trails ship in the product today.
Trust
This page is the company-level summary: how GRIFF AI & Co. approaches security and compliance as an organization. The detailed, control-by-control technical posture — with sources cited to audit artifacts and commits — lives on the product site.
Company-level posture
“SOC 2-track” and “FedRAMP-aligned” describe work in progress toward those standards, not the standards themselves. We do not use either phrase as a substitute for the real certification.
Governance-first is a stated operating principle, not a marketing line: named policy packs, human approval gates on sensitive actions, and hash-chained audit trails ship in the product today.
Every audited security finding on the product, with remediation status, is published on griff.run/trust and griff.run/security rather than kept in a private data room by default.
Controls are being built toward a SOC 2 Type I baseline (access control, change management, audit logging, incident response). No report exists yet. We will not claim SOC 2 compliance before an auditor issues one.
The product's federal readiness page maps live controls against NIST families as a starting posture for a federal pilot. This is control alignment work, not a FedRAMP authorization, and we say so on that page.
No completed third-party penetration test exists today. This is listed as a gap on the product /security page and stays listed here until it is closed.
No ISO 27001 or comparable formal certification is held. Certification work is procurement-conditional: it gets funded when a qualified pilot or federal engagement requires it.
What we do not claim
No SOC 2 report, no ISO 27001 certification, no completed independent penetration test, no FedRAMP authorization at any impact level, and no 24/7 on-call rotation. Best-effort triage by a single operator today. The full, sourced control-by-control accounting — including what live systems back each claim — is on griff.run/security.
Report an issue
Security issues in any GRIFF AI surface go to security@griff.run. We acknowledge receipt and work the issue in good faith; we do not currently run a paid bug bounty. Full disclosure terms are on the product security page. General company questions go through /contact.