Security and privacy
What FedXchange holds, and how it protects it
The short version
Not FedRAMP authorized, and designed with that in mind
Please don't put these in FedXchange
- Controlled Unclassified Information (CUI) or classified information
- System details such as addresses, host names, configurations, or findings
- Personal information beyond the names and work emails of the people who use it
For this reason, the System Security and Privacy Plan generator, which needs system details, stays out of the app.
What it holds
A short list, on purpose
About people
- Name and work email of each member
- Passkeys and two-factor settings they add
- Their role in the agency
About your agency
- The service you chose for each function
- Your titles for offices and roles
- Your decisions on governance changes
- The audit log of changes
From this website
- What you send through the contact or early-access form, kept 12 months
- No cookies, analytics, or advertising trackers on this site
The full details are in the privacy notice.
How it's protected
Controls built into the design
No passwords
People sign in with a link sent by email, a passkey, or both. Once someone sets up an authenticator app, an email link alone isn't enough.
One agency can't see another's data
Every record carries its agency's ID, and the service adds that ID to every query. No request can name a different agency. Tests check that one agency can't read another's records.
Roles decide what people can do
Each member is an owner, editor, reviewer, or viewer. AI assistants and access tokens act as the person who connected them, with that person's role.
Changes are previewed and recorded
Every change, from the web app, an assistant, or the governance watch, is written to your agency's audit log with who made it, how, and when.
Encrypted in transit and at rest
All traffic uses TLS. The database runs on Cloudflare D1, which encrypts stored data with AES-256.
Tokens are never stored in the clear
Personal access tokens are shown once and kept only as hashes. Assistant connections use one-hour tokens and end when you remove them.
Leaving
Your setup is yours
Found a security problem?
Tell us through the contact form and choose “Security report”. Please don't test against other people's accounts or data. We'll reply by email.