Security & compliance

Federal-grade data handling with a citation trail you can hand back.

Tributary runs on FedRAMP-aligned infrastructure with US-only data residency by default. Every line of a deliverable is linked back to a primary federal source — SAM.gov, the Federal Register, or Congress.gov — so your FOIA officer can audit the trail without re-work.

Platform posture

FedRAMP-aligned hosting, engineered for federal data.

We treat your procurement and rulemaking data as sensitive by default. The platform runs on FedRAMP-aligned infrastructure with the controls federal programs expect, so you can deploy Tributary inside an existing federal review pipeline without a separate security review for the underlying host.

  • Encryption at rest

    All customer data is encrypted at rest using AES-256 disk-level encryption, with managed key rotation handled by the underlying FedRAMP-aligned cloud.

  • Encryption in transit

    All client and inter-service traffic is encrypted in transit using TLS 1.2+ with a modern, AEAD cipher suite and HSTS on every public endpoint.

  • Role-based access control

    Least-privilege access via better-auth with per-workspace roles (owner, contributor, viewer, auditor). Every read and write is authorized against the caller’s userId + role, never a shared credential.

  • Audit logging

    Immutable, append-only audit log capturing timestamp, actor, action, and target object. Logs are exportable for review and retained for the same window as your data.

Citation trail

Every deliverable links back to a primary federal source.

A draft is only as good as its sources. Tributary writes against the authoritative federal record and stamps every line with a citation back to the source document. The same trail is what makes an export FOIA-ready — your officer hands back a document whose citations already resolve to a primary source, not a re-typed summary.

  • SAM.gov

    Solicitation metadata, attachments, amendments, and award notices → linked to the SAM.gov opportunity ID with canonical URL preserved verbatim.

  • Federal Register

    Proposed rules, final rules, notices, and public comments → linked to the document’s Federal Register page and paragraph anchor where available.

  • Congress.gov

    Bills, resolutions, committee record, and the Congressional Record → linked to the Congress.gov bill ID or Record page that the line was drawn from.

Data handling

Where your data lives, how long we keep it, and who else sees it.

Federal buyers ask three questions: where is the data, how long is it kept, and who besides us touches it. The answers are below in plain language.

  • Data residency

    Customer data is stored in US-only regions by default. GCC-High is available on the Enterprise plan for organizations that require it.

  • Retention window

    Project data and audit logs are retained for 30 months, aligned to the SAM.gov archive horizon for federal procurement records. Longer windows are available on Enterprise.

  • No model training on customer inputs

    Your inputs and your drafts are never used to train third-party models. Inference is isolated through the platform proxy and runs only against the model you selected for that workflow.

  • Third-party subprocessors

    Hosting (FedRAMP-aligned cloud), email delivery, payment processing, object storage, and uptime monitoring. The full subprocessor list, with current vendors, is available on request.

Security packet

Request our security packet.

Want the full packet? FedRAMP-aligned architecture diagram, SIG-lite questionnaire, and subprocessor list under NDA.

Send a note and we'll reply with the documents plus a named security reviewer on the first reply — usually within one business day.

Submissions route into a private intake queue. We do not share security-review traffic with mailing lists, ad networks, or third-party subprocessors outside of the hosting + delivery stack disclosed above.