Security and Compliance Documentation

Six Sense Solutions maintains transparency about our security posture, compliance alignment, and architecture so enterprise and government buyers can evaluate us without waiting for a sales call.

How we handle your data

Zero Credential Storage

Generated credentials exist only in memory during the API call and in the HTTP response returned to you. We never write, store, cache, or retain any generated credential. Ever.

No Password Logging

CloudWatch logs record request metadata only. Timestamp, key ID prefix, length requested, compliance profile, response time. Generated passwords never appear in any log.

Cryptographic Generation Only

Every credential is generated using Node.js crypto.randomInt() exclusively. Math.random() does not exist anywhere in our codebase. The source is auditable.

Encrypted at Rest

All persistent data including API keys and usage counters is stored in AWS DynamoDB with server-side encryption enabled using AWS managed keys.

Compliance framework alignment

Framework Status Details Documentation
NIST 800-63B Aligned Minimum length enforcement, character requirements, ambiguous character exclusion, entropy documentation per response Available in API response metadata
SOC2 Type II In Progress Password controls, audit logging, encryption at rest, access controls implemented Report pending
NIST SSDF Aligned Shift-left security practices, secure by design architecture, no Math.random() in codebase Available on request
CMMC Level 1 Preparing Access control, identification and authentication practices aligned Assessment pending
FedRAMP Roadmap AWS GovCloud deployment option on product roadmap Timeline available on request

Infrastructure and architecture

Cloud Provider

AWS us-east-1, with GovCloud deployment on roadmap

Compute

AWS Lambda with reserved concurrency cap and dead letter queue

Database

AWS DynamoDB with point-in-time recovery and encryption at rest

API Gateway

AWS API Gateway HTTP API v2 with custom domain and wildcard SSL

Logging

AWS CloudWatch with 30-day retention, no credential data ever logged

Infrastructure as Code

All resources managed with Terraform, auditable state in S3

Government procurement readiness

Download Capabilities Statement

Security inquiries

For security assessments, compliance documentation requests, or government procurement inquiries, contact us directly. We respond to all security and procurement inquiries within one business day.

Email: hello@sixsensesolutions.net

Contact Us