Security & Compliance Roadmap

Where We Are —Where We're Going

Transparent, dated progress on every security certification, compliance milestone, and control implementation. Built for procurement teams who need to plan ahead, not just see where we stand today.

14

Milestones Complete

6

In Progress

12

Planned Ahead

Last updated: May 2026 — reviewed monthly

Overall Security Program Progress

44% Complete
Complete (14)
In Progress (6)
Planned Q4 2026 (6)
2027 Roadmap (6)

Q2 2026

AES-256 Encryption at Rest

NIST SC-28

All user data encrypted at rest via Supabase (AWS us-east-1). Database, storage, and backups encrypted with AES-256.

TLS 1.3 Encryption in Transit

NIST SC-8

All client-server communication enforces TLS 1.3. Older TLS versions (1.0, 1.1) rejected at the edge.

Row-Level Security (RLS) Enforced

NIST AC-3

Supabase RLS policies deployed across all database tables. Users can only access their own records.

Immutable Audit Log (25+ Event Types)

NIST AU-2, AU-9

Append-only audit_log table covering auth events, data access, admin actions, document lifecycle, and payments.

Multi-Factor Authentication (MFA)

NIST IA-2(1)

TOTP and SMS MFA available for all users. Required for all specialist and admin accounts.

RBAC — 6 Role Definitions

NIST AC-2, AC-6

Role-based access control with 6 distinct roles: super_admin, admin, enterprise_user, ai_specialist, human_specialist, end_user.

Session Auto-Lock (15-min Inactivity)

NIST AC-11

Inactive sessions automatically locked after 15 minutes. Configurable per portal type. NIST AC-11 compliant.

FedRAMP SSP Public Summary Published

FedRAMP Moderate

31 NIST SP 800-53 Rev. 5 control implementation statements, FIPS 199 assessment, authorization boundary, and POA&M published.

Zero Trust Architecture (6 Tenets)

NIST 800-207 / EO 14028

NIST SP 800-207 ZTA implemented: verify explicitly, least privilege, assume breach, device/identity validation, encrypt everywhere, continuous monitoring.

CCPA / COPPA / GLBA Compliance Active

CCPA / COPPA / GLBA

California Consumer Privacy Act, COPPA youth account protections, and GLBA Safeguards Rule aligned. All user rights exercisable.

Data Breach Notification Policy Published

NIST IR-6

Full breach notification policy covering CCPA 72hr, GDPR 72hr, NIS2 24hr, GLBA 30-day, US-CERT deadlines and 7-step subscriber procedure.

Incident Response Plan Published

NIST IR-1 through IR-10

NIST SP 800-61 aligned IRP with 6 phases, 6 IRT role definitions, 6 incident type runbooks, and full escalation matrix.

Vendor Risk Management Policy Published

NIST SA-9

3-tier VRM policy with assessments of all 8 critical vendors (Supabase, Stripe, Plaid, Twilio, OpenAI, AWS, Shopify, Google Analytics).

Responsible AI Policy Published

NIST AI RMF / EU AI Act

6 core AI principles, prohibited uses, guardrails for Nova/Tundra/Vex/Echo/Aegis/Cipher, user rights, and AI governance structure.

Q3 2026

SOC 2 Type II — Audit Engagement

SOC 2 TSC CC6-CC9

Independent CPA firm engaged for SOC 2 Type II audit. Observation period begins Q3 2026. Trust Services Criteria: Security, Availability, Confidentiality.

Penetration Testing — First Annual

NIST CA-8

Independent third-party penetration testing firm engaged. Scope: web application, API layer, authentication, and Edge Function security.

FIPS 140-2 Cryptographic Module Verification

NIST SC-13

Verify and document FIPS 140-2 compliance path via AWS KMS + Supabase infrastructure layer. Required for FedRAMP Moderate authorization.

Privacy Impact Assessment — Annual Review

OMB A-130 / FedRAMP

Scheduled first annual PIA review. Update information type inventory, risk ratings, and retention schedules based on Q2 2026 platform additions.

Tabletop Incident Response Exercise

NIST IR-3

Semi-annual tabletop exercise with IRT. Scenario: P1 data exfiltration event. Validate response procedures and escalation chain from IRP.

EU AI Act — Risk Classification Assessment

EU AI Act 2024/1689

Formal assessment of Psychnex AI advisors under EU AI Act prohibited/high-risk/limited-risk categories. Legal counsel review of AI Act Article 6 applicability.

Q4 2026

SOC 2 Type II — Report Issued

SOC 2 Type II

SOC 2 Type II report expected Q4 2026 upon completion of audit observation period. Report will be available to enterprise clients under NDA.

MDM — Device Health Attestation

NIST AC-19, CISA ZTA Devices

Mobile Device Management (MDM) enrollment for all Psychnex-managed devices. Device health check required before accessing production systems. Closes CISA ZTA "Devices" pillar gap.

CMMC Level 2 — C3PAO Pre-Assessment

CMMC Level 2 / NIST 800-171

Engage a C3PAO (Third-Party Assessment Organization) for a pre-assessment review before formal CMMC Level 2 certification. Gap analysis and remediation plan delivered.

Continuous Monitoring Program (ConMon)

NIST CA-7, FedRAMP ConMon

Implement FedRAMP-aligned continuous monitoring: monthly vulnerability scanning, quarterly control reviews, annual penetration testing, and POA&M tracking.

Security Awareness Training — All Staff

NIST AT-2

Annual security awareness training program for all Psychnex employees. Covers phishing, social engineering, data handling, and incident reporting. NIST AT-2 compliant.

DPA Templates — Enterprise Standard

GDPR Art. 28 / CCPA

Standardized Data Processing Agreement templates for enterprise clients. GDPR Article 28 compliant, CCPA service provider terms, sub-processor schedule, and breach notification clauses.

2027

FedRAMP Moderate — Full Authorization

FedRAMP Moderate ATO

Submit FedRAMP Moderate Authorization To Operate (ATO) package to sponsoring agency. Achieve formal FedRAMP Moderate ATO. Enables government agency procurement.

CMMC Level 2 — Formal C3PAO Certification

CMMC Level 2 / 32 CFR Part 170

Complete formal CMMC Level 2 certification via C3PAO assessment. Enables DoD contractor and subcontractor use of Psychnex platform.

ISO 27001 Certification

ISO 27001:2022

Engage UKAS/IAF-accredited certification body for ISO 27001:2022 certification. Covers ISMS scope, risk assessment, and control implementation.

FIPS 140-3 Transition

FIPS 140-3 / NIST SC-13

Transition cryptographic module compliance from FIPS 140-2 to FIPS 140-3 (NIST standard updated 2019, enforcement timeline per agency requirements).

HIPAA BAA — Healthcare Portal

HIPAA §164.308

Execute Business Associate Agreement (BAA) for the Healthcare Portal. Enables full HIPAA-covered entity use cases for healthcare professional financial data.

EU AI Act — Compliance Registration

EU AI Act Art. 49

Complete EU AI Act compliance registration for high-risk AI systems (if applicable after Q3 2026 classification). Register with EU AI database per Article 49.

Roadmap Notice: This roadmap reflects Psychnex's current planning and is subject to change. Target dates are estimates based on current resource allocation and vendor timelines. Certification milestones depend on third-party auditor and assessment organization availability. Formal certifications (SOC 2 Type II, FedRAMP ATO, CMMC Level 2, ISO 27001) are not claimed until issued by the relevant certifying authority. Contact security@psychnex.com for current status on any milestone.

Planning a Government or Enterprise Procurement?

Contact our security team to get a current-state briefing, request milestone documentation, or ask about accelerated certification timelines.

Privacy & Consent

Talk with Us