Trust

Our posture at the company level, with the gaps named out loud.

This page is the company-level summary: how GRIFF AI & Co. approaches security and compliance as an organization. The detailed, control-by-control technical posture — with sources cited to audit artifacts and commits — lives on the product site.

Company-level posture

Six areas, rated honestly.

“SOC 2-track” and “FedRAMP-aligned” describe work in progress toward those standards, not the standards themselves. We do not use either phrase as a substitute for the real certification.

Governance operating model

In place

Governance-first is a stated operating principle, not a marketing line: named policy packs, human approval gates on sensitive actions, and hash-chained audit trails ship in the product today.

Public findings disclosure

In place

Every audited security finding on the product, with remediation status, is published on griff.run/trust and griff.run/security rather than kept in a private data room by default.

SOC 2 readiness track

In progress

Controls are being built toward a SOC 2 Type I baseline (access control, change management, audit logging, incident response). No report exists yet. We will not claim SOC 2 compliance before an auditor issues one.

FedRAMP-aligned control mapping

In progress

The product's federal readiness page maps live controls against NIST families as a starting posture for a federal pilot. This is control alignment work, not a FedRAMP authorization, and we say so on that page.

Independent penetration test

Not yet

No completed third-party penetration test exists today. This is listed as a gap on the product /security page and stays listed here until it is closed.

ISO 27001 / formal certification

Not yet

No ISO 27001 or comparable formal certification is held. Certification work is procurement-conditional: it gets funded when a qualified pilot or federal engagement requires it.

What we do not claim

No SOC 2 report, no ISO 27001 certification, no completed independent penetration test, no FedRAMP authorization at any impact level, and no 24/7 on-call rotation. Best-effort triage by a single operator today. The full, sourced control-by-control accounting — including what live systems back each claim — is on griff.run/security.

Report an issue

Found a problem? We want to hear it.

Security issues in any GRIFF AI surface go to security@griff.run. We acknowledge receipt and work the issue in good faith; we do not currently run a paid bug bounty. Full disclosure terms are on the product security page. General company questions go through /contact.