Audit & Transparency
We state our compliance posture exactly as it is — no inflated claims, no certification theater. Every SOC-relevant artifact is exported to our COMPLIANCE-locked evidence bucket and timestamped before it is considered evidence.
SOC 2 Posture
Status: Controls Implemented — Formal Audit Not Yet Completed
MovingOrders has implemented controls aligned to the SOC 2 framework across the Security, Availability, and Confidentiality trust service categories. A formal third-party audit has not yet been completed. This statement reflects our implemented control posture only.
FedRAMP Alignment
Status: Aligned to FedRAMP Moderate Baseline — Formal Authorization Not Yet Initiated
MovingOrders infrastructure aligns to FedRAMP Moderate control baseline as groundwork for the MEMBER-FEDERAL tier. The formal FedRAMP authorization process begins November 11, 2026 (Veterans Day). AWS services underpinning MovingOrders independently hold FedRAMP High ATO. MovingOrders itself does not hold a FedRAMP authorization at this time.
Immutable Audit Trail
Every action on the platform writes to an append-only audit table. Database policies enforce DELETE USING (FALSE) on audit, inquiry, consent ledger, moderation, governor release log, flag audit, and evidence export tables. These tables cannot be updated or deleted — only appended to.