TRUST CENTER

Trust, audited and on a timeline.

Thabit sells to regulated industries (defense, aerospace, and critical-infrastructure engineers. Compliance isn't a marketing badge) it's a precondition. This page shows every framework we're pursuing, what it unlocks, and when we expect to achieve it. Dates are aggressive but honest.

LAST UPDATED · APRIL 17, 2026

Compliance Roadmap

FrameworkStatusTargetWhat it unlocks
SOC 2 Type IIN PROGRESSQ3 2026Baseline security attestation, unblocks most Team-tier procurements.
SOC 2 Type IIROADMAPQ4 202612-month observation period; required by most Enterprise buyers.
CMMC Level 2 (self)ROADMAPQ1 2027Required for subcontractors handling CUI under DFARS 252.204-7012.
CMMC Level 2 (C3PAO)ROADMAPQ3 2027Third-party certification for contracts above $1M.
FedRAMP 20x ModerateROADMAPQ4 2027Federal-agency direct sales via automated continuous authorization.
FedRAMP High / DoD IL-4ROADMAP2028Higher-impact federal systems including DoD CUI.
DoD IL-5ROADMAP2028+Non-public national-security data; sponsor-program-specific.

Current Security Practices

Every item below is in production today. For the architectural explanation of each, see the Security Overview.

CategoryPractice
EncryptionTLS 1.3 in transit; AES-256 at rest on database, object storage, and backups.
AccessRole-based access with row-level tenant isolation; MFA for all admin access.
SecretsManaged secret store; no secrets in source control; quarterly rotation schedule.
LoggingStructured application logs + cloud audit logs, 1-year retention, append-only.
MonitoringReal-time error tracking with PII scrubbing; anomaly alerting on auth events.
SDLCPeer review on every merge; automated dependency scanning; secrets scanning; static analysis.
BackupsAutomated backups with 30-day point-in-time recovery; semi-annual DR drill.
PeopleBackground checks for production access; annual security awareness training.

Documents Available on Request

  • Security questionnaire responses, SIG Lite, CAIQ, and custom questionnaires within 5 business days.
  • Penetration test summary, annual third-party engagement, available under NDA.
  • Business Continuity and Disaster Recovery Plan, summary version available under NDA.
  • Data Processing Addendum (DPA), public template, executable with enterprise customers.
  • SOC 2 Type I report, available upon issuance (Q3 2026) under NDA.

Request any of the above by emailing security@thabit.ai.

How We Stay Honest

  • Vanta continuous monitoring auto-collects evidence for every control, continuously, no annual scramble.
  • Incident response runbook is exercised quarterly (tabletop) and annually (full drill).
  • Quarterly access reviews on all production systems.
  • Public subprocessor list at /legal/subprocessors, updated before any change takes effect.
  • Responsible disclosure program with safe-harbor commitments, details here.

Regulatory Handling Guidance

Thabit’s Services are not yet authorized for: classified data (any level), Controlled Unclassified Information (CUI) subject to DFARS 252.204-7012, ITAR-controlled data, PHI subject to HIPAA, or PCI cardholder data. Our roadmap above sets the dates each category becomes permissible. Customers are responsible for verifying authorization status before uploading regulated content; see the AUP for the full restricted-content policy.