Back

Trust and security position

Clear controls before controlled data.

This page separates implemented demo controls from production controls that still need to be deployed and verified before paid customers upload sensitive manufacturing packages.

Current boundary

Do not upload ITAR, CUI, CDI, classified, export-controlled, or production-sensitive data until the production control set is live.

Verified Today

Demo mode uses fake sourcing data and must not receive real controlled technical data.

The metal quote backend writes server-side audit events for estimates, RFQs, reviews, quotes, approvals, payments, and access requests.

Instant estimates are explicitly budgetary and require human/admin review before final quote, payment, or order creation.

A low-idle AWS Terraform stack now defines Cognito, DynamoDB, private S3 storage, signed URLs, and a Lambda Function URL API.

Mock payments are isolated from live payment processors until a real provider is wired and reviewed.

Required For Production

Apply the Terraform stack, create pilot users, and assign Cognito groups with tenant IDs.

Wire the deployed API URL and Cognito outputs into Cloudflare Pages environment variables.

Replace dashboard demo state with authenticated API calls before exposing non-demo data.

Validate production access procedures with signed document URLs and server-side audit exports.

Publish a control-backed security page only after the deployed controls are verified.

Claims Avoided

Sovereign Source does not certify ITAR, CMMC, Nadcap, AS9100, JCP, or supplier compliance.

The system does not promise autonomous compliance verification or real-time registry checks.

The demo is not approved for ITAR, CUI, CDI, export-controlled, or classified data.

Budgetary estimates are not guaranteed final prices, lead times, or manufacturability decisions.

Pilot access starts with a review.

The safest first conversion path is a reviewed pilot, not an open self-serve upload flow.

Request pilot access