Government-grade protection for the data you can't afford to lose.
Every pursuit you run through GovHub carries your proprietary strategy, your pricing logic, and your customer's requirements. That data sits on infrastructure built and continuously monitored against the same frameworks your own customers hold you to. Plain English first. Full technical detail below. Nothing on this page is rounded up — including the parts we haven't finished.
Monitored continuously, not annually.
A certification is a photograph. It tells you what was true on the day the auditor visited. Between visits, the honest answer for most vendors is that nobody is looking.
Our production AWS environment is monitored continuously by Orca Security for configuration drift, vulnerability exposure, and cloud misconfiguration — alongside AWS GuardDuty, Security Hub, Config, and CloudTrail. Orca measures our environment against the control catalogs behind SOC 2, ISO 27001, NIST 800-171, FedRAMP, and CMMC Level 2. Findings are reviewed on a defined cadence and tracked to remediation, or documented as accepted exceptions with business justification.
This is the part of our security posture we're most willing to be judged on today, because it's the part that's true every day rather than one day a year. It is also, precisely, a continuous posture assessment — not a certification or authorization of GovHub OnDemand. Our monitoring vendor has confirmed directly that its coverage does not extend to administrative controls such as HR checks, training, or written policy; those are addressed by our own security program.
Built on infrastructure that is already authorized.
GovHub runs on Amazon Web Services in United States regions — us-east-1 as the primary production region, with us-west-2 for disaster recovery and file replication. AWS infrastructure holds FedRAMP authorization, SOC audit reports, and ISO 27001 certification, which means the physical security, network architecture, and hypervisor layer beneath GovHub are controls we inherit rather than reinvent.
GovHub does not operate in AWS GovCloud. All workloads run in standard AWS commercial regions within the United States. We state that explicitly because the distinction matters to federal buyers and we won't leave it ambiguous.
Here is the line most vendors blur: infrastructure certifications cover the infrastructure. They do not transfer to the application running on top. AWS certifies AWS. Amerix certifies Amerix — separately, on its own audit clock, and as the operator of the service Amerix is the party that will hold those certifications. What inheritance actually buys is a smaller and faster scope for our own. It buys us a head start. It does not buy us a badge.
For your security reviewer.
The section you forward. Expand what you need — including the four places we tell you what isn't finished.
- At rest: customer files, deliverables, and the application database are encrypted with AWS KMS customer-managed keys, with automatic rotation enabled.
- Application secrets — database credentials, API keys, token signing keys — are held in AWS Secrets Manager and rotate every 90 days. They are never stored in source code.
- Audit logs and backups are encrypted with the same customer-managed keys.
- Passwords are stored as irreversible hashes. Plaintext is never stored, and passwords, one-time codes, and tokens are never written to logs.
- Database records for pursuits, company profiles, agent outputs, and billing are scoped to the owning account.
- Server-side authorization checks scope every API request to its owning account — one customer cannot read another customer's work through the API.
- Uploaded files and generated deliverables are stored under account-specific paths.
- AI processing for a pursuit runs only in the context of that account's own data.
- Files uploaded to our storage are scanned for malware by AWS GuardDuty Malware Protection, in both production and staging, with scan results tagged on each file.
- GuardDuty Malware Protection is additionally enabled for account-level threat detection and disk-level malware checks.
- Container images are scanned automatically on every push, and the deployment pipeline blocks any build containing a CRITICAL vulnerability.
- Multifactor authentication and single sign-on are required for all human access to the production AWS account.
- Production services run under IAM roles with least-privilege permissions and no long-lived credentials.
- The production database is not reachable from the public internet.
- Security headers include HSTS, X-Frame-Options, Content-Security-Policy, and X-Content-Type-Options.
- Failed logins and related security events are recorded for investigation.
- Three-tier private network design: a public edge for load balancers, a private tier for application containers with no direct internet access, and an isolated data tier — across two availability zones.
- HTTPS-only load balancer fronted by AWS WAF running the OWASP Core Rule Set.
- Encrypted PostgreSQL, multi-AZ for high availability, SSL required, not publicly reachable.
- Encrypted object storage with public access blocked; CloudFront for media delivery.
- Multi-region AWS CloudTrail with log file validation, 365-day audit log retention, and 90-day VPC flow logs.
- Amazon GuardDuty, AWS Security Hub, and AWS Config, with HIGH and CRITICAL findings triggering real-time alerts.
- All code lives in version control behind a protected main branch, and every change requires pull-request review before merge.
- Automated tests and security scanning run on every build; a CRITICAL vulnerability blocks the deployment.
- Infrastructure is managed as code, with every plan reviewed before it is applied.
- Production deployments require manual approval from two reviewers.
- Container images carry immutable commit-based tags, so any deployed artifact traces back to its exact source.
- Deployments are rolling with health checks; rollback is immediate because previous images are retained.
- Pipeline authentication uses federated identity — no long-lived cloud access keys are stored in the build system.
- Automated database backups with point-in-time recovery across a 30-day window.
- Daily encrypted backups to a separate, dedicated AWS Backup vault.
- File versioning plus replication to a second US region.
- Multi-AZ database with automatic failover; application containers auto-heal across availability zones.
- What would trigger notifying you: confirmed unauthorized access to your data, or a confirmed breach of tenant isolation.
- Responsible disclosure: if you discover a vulnerability, report it to support@amerix.ai. We acknowledge within two business days and prioritize remediation by severity. We will not pursue action against researchers acting in good faith who avoid privacy violations and service disruption and give us reasonable time to remediate.
- Remediation targets: CRITICAL in 7 days, HIGH in 30, MEDIUM in 90.
What GovHub is not built to hold.
Two rules, stated plainly because your compliance officer will ask.
Everything else — solicitations, your own proposal content, your capability library, your win history, your pricing strategy — is exactly what the platform is built to handle.