Zum Inhalt springen
NavTrax Expeditions-Betriebssystem

Defense · Assurance · Whitepaper

Stated plainly. Including the gaps.

Most vendors publish a compliance page that implies certifications they do not hold. This one states where NavTrax stands, what is in progress, and what is not yet begun — because a procurement officer will find out either way, and finding out late is worse for both of us.

What we are designing against.

Three claims are routinely made and rarely true.

"FIPS compliant." FIPS 140 validation applies to a cryptographic module, not to an application. An application can use a validated module; it cannot itself be validated. Wording that blurs this is the most common misrepresentation in the category.

"CMMC certified." CMMC certification applies to an organization handling controlled unclassified information, assessed by a third party. A software product is not CMMC certified; a company is.

"SOC 2 compliant." SOC 2 is a report over a defined period against selected trust criteria, issued by an auditor. Without the period and the criteria, the phrase carries no information.

The design, stated so it can be evaluated.

What we hold today
Nothing that we have not been assessed for. We will not list a framework we are working towards as though it were achieved.
FIPS
The platform is architected to use a FIPS 140-3 validated cryptographic module for data at rest and in transit in an Enterprise deployment. Module validation belongs to the module vendor; our claim is limited to using one and to documenting which.
NIST SP 800-171
A control-by-control self-assessment with a documented system security plan and plan of action is the deliverable we can provide today for a CUI environment.
CMMC
Organisational readiness work is in progress. We will state a level when we have been assessed for one, not before.
SOC 2
Type II is planned. The trust criteria and the observation period will be published with the report.
Audit logging
Available today on Enterprise: every user and administrative action recorded with actor, timestamp and origin, exportable, and covering failed attempts as well as successful ones.
Data sovereignty
Tenant data location is a deployment parameter. In an air-gapped deployment it never leaves the network, which is a stronger statement than any residency clause.
Accreditation support
SBOM, STIG-aligned baselines and signed delivery packages are provided to support an ATO process. We do not claim an ATO we have not been granted.

What is actually delivered.

01

Audit logging

Available now on Enterprise, including failed attempts.

02

Data residency as configuration

Including a deployment with no egress at all.

03

SBOM with every release

So the receiving authority can assess what is introduced.

04

STIG-aligned baselines

Shipped as configuration, not as guidance.

05

Signed delivery

Verifiable provenance on removable media.

06

800-171 self-assessment

With an SSP and a plan of action.

07

No overstated claims

If it is not on the table below, we do not have it.

Compliance status, stated without inflation
FrameworkStatusWhat that means
FIPS 140-3Architected to use a validated moduleModule validation is the module vendor’s
NIST SP 800-171Self-assessment availableSSP and plan of action provided
CMMCReadiness in progressNo level claimed until assessed
SOC 2 Type IIPlannedCriteria and period published with the report
ATOSupport providedSBOM, baselines, signed delivery
Audit loggingAvailable nowEnterprise tier
Data sovereigntyConfigurableAir-gapped means no egress

Traced, node by node.

Compliance posture — relevant process graph Ziehen zum Schwenken · ⌘/Ctrl + Scroll zum Zoomen · Knoten ziehen zum Verschieben

We would rather lose a deal than a reputation.

Audit logging, sovereignty controls and accreditation support are Enterprise. Ask us directly about anything above.