Security & Compliance Overview

Security Overview

This document is an informational overview and does not create independent contractual warranties. Customer-specific commitments are governed by the applicable EULA, Mutual Non-Disclosure Agreement, order form, CabletequeGov Compliance Addendum, and/or AI Feature Addendum.

1. Security Commitment

Cableteque designs its platform with security as a foundational requirement. Our customer base includes both commercial manufacturers and highly regulated defense organizations, and our security controls reflect the needs of both segments. Cableteque maintains two distinct deployment environments, the Commercial environment and CabletequeGov, each with controls appropriate to its use.

This document provides an overview of Cableteque's security architecture, data protection practices, and compliance posture. For AI-specific data handling commitments, see the AI & Data Policy.

2. Platform Architecture

2.1 Deployment Environments

Cableteque operates two separate environments. The Commercial environment supports ordinary commercial workloads. CabletequeGov is designed to support CUI, CDI, ITAR and approved export-controlled workloads under applicable customer terms. CabletequeGov is hosted on AWS GovCloud (U.S.), with defined processing functions performed in U.S.-only regions of Azure Government and Google Cloud Assured Workloads. All processing of Licensee Data within the CabletequeGov service boundary occurs within U.S. regions.

Environment

Purpose

Infrastructure

Commercial

Ordinary commercial workloads for wire harness manufacturers

Commercial regions of AWS, Azure and Google Cloud

CabletequeGov

CUI, CDI, ITAR and approved export-controlled workloads under applicable customer terms

AWS GovCloud (U.S.), with defined processing functions in U.S.-only regions of Azure Government and Google Cloud Assured Workloads

An independent FedRAMP® Moderate Equivalency assessment is being conducted by Ignyte Assurance Platform. Cableteque expects the full audit to occur in November 2026, with full 3PAO-validated Body of Evidence, and other documentation required under applicable DoD FedRAMP Moderate Equivalency guidance, targeted for completion in December 2026. Target dates are planning objectives.

CabletequeGov was approved as FedRAMP® Ready on July 27, 2026, and is listed on the FedRAMP® Marketplace (Package ID FR2620331565). Following the FedRAMP® program's 2026 transition, the Marketplace designates Rev 5 Ready listings as "Legacy FedRAMP® Ready" (Class C/Moderate, Agency path, effective July 28, 2026). The Readiness Assessment was performed by Ignyte Assurance Platform, an accredited Third-Party Assessment Organization, against the FedRAMP Moderate baseline covering the full CabletequeGov system boundary: infrastructure, platform, and application. The FedRAMP® Program Management Office reviewed the results and identified no concerns.

See the official FedRAMP Marketplace listing (Package ID FR2620331565).

2.2 Cloud Provider Security Foundation

By building on AWS, Azure, and Google Cloud, Cableteque builds on providers that maintain their own security and compliance programs. Depending on the applicable service and authorization boundary, these providers hold certifications and authorizations, including SOC 1/2/3, ISO 27001/27017/27018, FedRAMP® Moderate and High, DoD SRG, FISMA, FIPS-validated cryptographic modules, and DFARS/CUI compliance programs, each as stated in the applicable provider package. A list of AWS compliance programs is available at aws.amazon.com/compliance/programs.

Cloud-provider certifications and authorizations apply only to the provider services and authorization boundaries identified in the applicable provider package. Cableteque's use of an authorized cloud service does not, by itself, certify or authorize CabletequeGov.

3. Data Protection

Cableteque protects customer data throughout its lifecycle.

3.1 Encryption

Licensee Data is encrypted in transit using TLS 1.2 or higher, or other approved cryptographic protocols appropriate to the applicable service, and at rest using cloud-native key-management services governed by Cableteque-controlled access policies. CabletequeGov uses cryptographic modules validated to FIPS 140-3 and listed in the NIST Cryptographic Module Validation Program.

3.2 Data Isolation

Customer data is logically segregated at the database and API layer using unique customer identifiers. Access controls are designed and tested to prevent one customer's data from being accessible to another customer, and segregation controls are reviewed as part of Cableteque's security testing program.

3.3 Retention, Deletion and Post-Termination

Licensee Data is retained during the active subscription. Following expiration or termination, Cableteque will make Licensee Data available for retrieval for thirty (30) days in a commonly used, machine-readable format and will provide commercially reasonable retrieval assistance. Upon written request after the retrieval period, Cableteque will delete Licensee Data from active systems and provide written confirmation of deletion. Residual copies in routine backups, security records, legal holds, and approved provider systems are governed by applicable retention schedules and remain protected until deleted in the ordinary course.

Deletion from active systems is performed using industry-standard secure deletion methods consistent with applicable data protection regulations.

4. Identity & Access Management

Access Controls: Role-based access controls restrict system access to authorized personnel.

Authentication: Secure authentication practices, including multi-factor authentication for privileged access, are enforced across production systems.

Least Privilege: Routine direct administrative access to production Licensee Data is disabled. Time-bound, least-privilege access may be granted to authorized personnel for approved support, security, legal, or incident-response purposes, and such access is logged and reviewed.

Audit Logging: Access to production systems and customer data is logged via platform-native logging services (e.g., AWS CloudTrail) and retained in accordance with applicable retention schedules for compliance review.

5. Secure Development

Secure Coding: Cableteque integrates security into its software development lifecycle, including secure coding standards, automated vulnerability scanning, and peer code review.

Vulnerability Management: Anti-malware and vulnerability scanning are performed against platform code and software components in the deployment pipeline, with findings triaged and tracked to remediation.

Patch Management: Security patches are applied on a risk-prioritized schedule with defined remediation timelines for critical findings.

6. Security Monitoring & Incident Response

Continuous Monitoring: Activity monitoring, vulnerability scanning, and anomaly detection are deployed across platform infrastructure within the defined system boundary, including AI pipelines.

Incident Response: Cableteque maintains structured incident response procedures to identify, contain, and remediate security events in accordance with applicable regulations.

Breach Notification: In the event of a security incident affecting customer data, Cableteque will notify affected customers in accordance with applicable legal obligations and the terms of the governing agreement.

6.1 DFARS Incident Support

Cableteque supports Licensee's obligations under DFARS 252.204-7012(c)–(g). Cableteque will notify Licensee's designated point of contact as soon as reasonably practicable, and in no event later than forty-eight (48) hours after discovery of a cyber incident affecting Licensee Data that Cableteque reasonably believes may be reportable under DFARS 252.204-7012. Upon discovery of such an incident, Cableteque will promptly preserve and protect relevant system images, logs, monitoring data, and other evidence reasonably necessary to support investigation and reporting, and will retain such materials for at least ninety (90) days following submission of the applicable cyber-incident report to DoD. Cableteque will also support malicious software submission to DC3 at the Licensee's direction and cooperate with reasonable forensic and damage assessment requirements. Reporting to DoD, including DIBNet submission and maintenance of a DoD-approved medium-assurance certificate, remains Licensee's obligation as the contractor.

7. Business Continuity

Backup & Recovery: Customer data is backed up on a defined schedule, with documented recovery time objectives and recovery point objectives.

Failover: Platform availability is supported by redundant infrastructure and failover mechanisms across cloud regions.

Testing: Business continuity and disaster recovery capabilities are tested periodically, and test results are used to update recovery procedures.

8. Third-Party Risk

Third-party providers with access to customer data are subject to a security assessment prior to engagement, and Cableteque's Security Officer maintains a registry of approved providers.

Providers that process Licensee Data are governed by written service, confidentiality, security, and data-use terms appropriate to their role. AI providers are prohibited from using Licensee Data to train or fine-tune their own or any generally available artificial intelligence or machine learning models or services.

9. Compliance Posture & Roadmap

Cableteque's independent assurance programs are intended to meet the FedRAMP® Moderate Equivalency and ISO/IEC 27001 requirements.

Framework

Status

Scope

Notes

Legacy FedRAMP® Ready — Class C (Moderate)

Listed on the FedRAMP Marketplace

CabletequeGov

CabletequeGov is listed on the FedRAMP® Marketplace as Legacy FedRAMP® Ready at the Moderate impact level (Package ID FR2620331565). Approved FedRAMP® Ready on July 27, 2026; Readiness Assessment performed by Ignyte Assurance Platform, an accredited Third-Party Assessment Organization, against the FedRAMP Moderate baseline covering the full CabletequeGov system boundary: infrastructure, platform, and application. The FedRAMP Program Management Office reviewed the results and identified no concerns. See §9.1 for what this designation does and does not mean.

FedRAMP Moderate Equivalency

Assessment in progress

CabletequeGov

An independent FedRAMP® Moderate Equivalency assessment is being conducted by Ignyte Assurance Platform. Cableteque expects the full audit to occur in November 2026, with the full 3PAO-validated Body of Evidence, including the System Security Plan, Security Assessment Plan, Security Assessment Report, Customer Responsibility Matrix, and other documentation required under applicable DoD FedRAMP® Moderate Equivalency guidance, targeted for completion by December 2026. Target dates are planning objectives.

NIST SP 800-53 Rev 5, Moderate baseline

Controls implemented; independent control-effectiveness assessment is active

CabletequeGov

Controls corresponding to the Moderate baseline are implemented across the CabletequeGov boundary. Independent assessment of control effectiveness is being performed as part of the Equivalency engagement described above.

ISO/IEC 27001

Certification in progress

All environments

ISO/IEC 27001 certification across all Cableteque environments is in progress, with completion targeted by the end of 2026, and Ignyte Assurance Platform engaged for ISMS implementation support and the certification audit.

 

9.1 What Legacy FedRAMP® Ready means and what it does not

This is the question we are asked most often, and it deserves a direct answer rather than a marketing one.

Legacy FedRAMP® Ready is not a FedRAMP® Certification and is not a completed FedRAMP Moderate Equivalency. It reflects an accredited assessor's evaluation that the required technical capabilities are implemented across the assessed boundary. Customers are responsible for determining, based on their applicable contracts, regulatory obligations, assessment requirements, intended data, and risk posture, whether CabletequeGov's current compliance posture is appropriate for their use. Some customers determine that the currently available independent evidence is sufficient for their use; others require a completed FedRAMP® Moderate Equivalency Body of Evidence before placing regulated data in an external cloud. Where applicable law or a binding contractual requirement expressly requires a FedRAMP® Moderate Certified or FedRAMP® Moderate equivalent service, that requirement remains controlling.

To state explicitly what Legacy FedRAMP® Ready is:

It is an accredited 3PAO's evaluation, reviewed by the FedRAMP® PMO without identified concerns, that the required technical controls are implemented across the assessed CabletequeGov boundary: infrastructure, platform, and application.

Cableteque makes no claim of U.S. Government endorsement, and makes no exclusivity claim of any kind in connection with its FedRAMP® status. The authoritative record is the FedRAMP Marketplace listing (Package ID FR2620331565).

9.2 Evidence Availability

The following are available to Licensee on request, under an executed non-disclosure agreement where appropriate: the Ignyte Third-Party Assessment Organization letter documenting the completed Readiness Assessment; the FedRAMP® Marketplace listing and published readiness assessment; a description of the CabletequeGov environment, architecture and control implementation; and direct engagement between Cableteque's security team and Licensee's assessors. The complete 3PAO-validated Body of Evidence will be made available under an executed non-disclosure agreement following completion of the Equivalency assessment.

9.3 Assessor Cooperation

Cableteque will engage directly with Licensee's C3PAO or CMMC consultant and will respond to reasonable requests for evidence and clarification in support of Licensee's assessment.

10. Shared Responsibility

Cableteque operates under a shared-responsibility model. Cableteque is responsible for implementing and operating the security controls within the Cableteque-managed service boundary and for protecting Licensee Data in accordance with the applicable governing agreements. Underlying cloud providers remain responsible for controls within their respective service boundaries.

Licensee is responsible for determining whether CabletequeGov's then-current compliance and assessment status is sufficient for Licensee's applicable contracts, regulatory obligations, assessment requirements, intended data, and risk posture before submitting regulated data.

All Licensee Data is treated as confidential and proprietary by default, regardless of labeling. Licensee remains responsible for determining whether its data is subject to CUI, CDI, ITAR, EAR, or other regulatory restrictions, for identifying such data before submission, and for ensuring that its users are appropriately authorized.

Customers retain responsibility for:

Managing user account credentials and access within their organization.

Ensuring authorized users are trained on the appropriate use of the platform.

Classifying and managing export-controlled or regulated content in accordance with applicable law, including ensuring such content is submitted only through CabletequeGov.

Reviewing, validating, and verifying AI-generated and other outputs before use in engineering, manufacturing, quoting, procurement, or operational decisions.

11. Contact

For security and compliance inquiries, to request compliance documentation, or to report a security concern:

General Support: support@cableteque.com

Legal & Compliance: legal@cableteque.com

Security Reports: support@cableteque.com

Legal Hub: cableteque.com/legal