MovingOrders
← Trust Center
COMPLIANCE

Audit & Transparency

We state our compliance posture exactly as it is — no inflated claims, no certification theater. Every SOC-relevant artifact is exported to our COMPLIANCE-locked evidence bucket and timestamped before it is considered evidence.

SOC 2 Posture

Status: Controls Implemented — Formal Audit Not Yet Completed

MovingOrders has implemented controls aligned to the SOC 2 framework across the Security, Availability, and Confidentiality trust service categories. A formal third-party audit has not yet been completed. This statement reflects our implemented control posture only.

Security (CC)
Implemented
Availability (A)
Implemented
Confidentiality (C)
Implemented
Formal audit
Not yet completed

FedRAMP Alignment

Status: Aligned to FedRAMP Moderate Baseline — Formal Authorization Not Yet Initiated

MovingOrders infrastructure aligns to FedRAMP Moderate control baseline as groundwork for the MEMBER-FEDERAL tier. The formal FedRAMP authorization process begins November 11, 2026 (Veterans Day). AWS services underpinning MovingOrders independently hold FedRAMP High ATO. MovingOrders itself does not hold a FedRAMP authorization at this time.

Immutable Audit Trail

Every action on the platform writes to an append-only audit table. Database policies enforce DELETE USING (FALSE) on audit, inquiry, consent ledger, moderation, governor release log, flag audit, and evidence export tables. These tables cannot be updated or deleted — only appended to.

Retention period7 years (COMPLIANCE object lock)
Storages3://alpha-prod-mo-evidence-east1
EncryptionAWS KMS — SSE-KMS
Audit table mutabilityAppend-only — DELETE USING (FALSE)
Flag audit trailActor + timestamp + reason — every toggle
Governor release logImmutable — every aggregate exit recorded

NIST 800-53 Control Families Referenced

AC — Access ControlAU — Audit and AccountabilityCM — Configuration ManagementIA — Identification and AuthenticationIR — Incident ResponseMA — MaintenanceMP — Media ProtectionPL — PlanningPS — Personnel SecurityRA — Risk AssessmentSA — System AcquisitionSC — System and CommunicationsSI — System and Information Integrity

Algorithm of Trust™ — ARCEB

A
Auditable
Immutable 7-year audit trail on every agent action
R
Reversible
Every agent action reversible within defined windows
C
Compliant
Pre-execution compliance gate — never post-hoc
E
Explainable
Plain-language reasoning chain on every decision
B
Bounded
Agent cannot exceed its defined scope — enforced in registry