Specset — FedRAMP Public Information

Specset Cloud Platform (SCP) · FedRAMP 20x · Initial Implementation · last generated 2026-09-14

Machine-readable format: https://specset.com/fedramp/fedramp.json
Conforms to the FedRAMP Certification Package Overview schema (2026-06-24). Served as application/json with no authentication, approval workflow, or access justification required.

This page publishes the information required by FedRAMP CDS-CSO-PUB (Public Information). Every enumerated field is listed below; fields that do not yet apply to Specset's current stage are stated explicitly rather than omitted.

FedRAMP IDFR2631258135
FedRAMP Marketplace listing
Service ModelSaaS
Deployment ModelPublic Cloud
Business CategoryArtificial Intelligence (AI), Construction
UEI NumberS7RZBSZXNBD5
Sales Contact Informationsales@specset.com
Security Contact InformationFedRAMP Security Inbox · fedramp@specset.com
Product Websitehttps://specset.com
Product Logohttps://specset.com/fedramp/specset-logo.png
Overall Service DescriptionThe Specset Cloud Platform is an AI platform for construction document review. It automates technical review across project manuals, drawing sheets and shop drawings: submittal review against project specifications, UFGS (Unified Facilities Guide Specifications) compliance checking, design review automation, asset management logic, and search and question answering across a project's documents. The platform flags potential issues and returns cited answers drawn from the customer's own project documents. Specset is the trade name of Spot.xyz Corporation, formerly Specbook. The SOC 2 Type II report supporting this package is issued to Spot.xyz Corporation DBA Specset, and the Unique Entity Identifier above is registered to that entity. FedRAMP ID FR2631258135 is the sole active Marketplace listing for this offering; a duplicate listing created at intake, FR2631747321, is pending retirement, requested 2026-08-31.
Services and Security Categories
ServiceDescriptionAvailable since
Specset Cloud PlatformThe Specset Cloud Platform is a single multi-tenant SaaS service for construction document intelligence. Security category: Moderate (FIPS 199), reflecting the Controlled Unclassified Information the service handles for defense and federal customers. The platform is offered as a single service, and no component of it carries a different security category. It ingests customer project documents (project manuals and specifications, drawing sheets, shop drawings and submittals) and provides automated submittal review against project specifications, UFGS and specification compliance checking, design review automation, document search and question answering across a project's documents, and asset management logic. Customers use the service through a web application. Optional customer-initiated integrations connect to the customer's own Procore or Autodesk tenants. Production runs on Google Cloud Platform in project specset-prod-assured (Assured Workloads, FEDRAMP_MODERATE control package, us-west1), with supporting services on Amazon Web Services and Microsoft Azure as listed under third-party information resources. A per-organization CUI mode restricts model, embedding and web-grounding calls to the Assured Workloads project (Vertex AI, location us), disables the commercial AI and support-chat integrations and the customer-initiated Procore and Autodesk integrations, and never calls Perplexity. Federal tenants are provisioned with CUI mode enabled.2025-01-22
Secure Configuration GuidanceNot required at Class A (SCG-CSO rules apply from Class B); published before the Class C application.
Documentation Overview
DocumentTypeSummaryAvailability
Security Decision Record (SDR)JSON + Markdown (FedRAMP 2026-06-24 schema)Per-rule and per-KSI implementation, validation and assessment statements for the Class A package, with SOC 2 Type II control mappings and a gap statement for each partially implemented rule.Supplied with the Class A application; published as a restricted trust-center resource, no NDA, when that application is filed
Ongoing Certification Report (OCR) — exampleJSON + Markdown (FedRAMP 2026-06-24 schema)Schema-conformant example of the quarterly report of certification-data changes, planned changes, accepted vulnerabilities, agencies and reportable incidents, labeled as an example. The first report is due 2026-12-01.Supplied with the Class A application; published as a restricted trust-center resource, no NDA, when that application is filed
Information-resources inventory (MAS-CSO-IIR)JSON + Markdown (generated), with generator, sources and derivation methodEvery cloud account, project and third-party service that handles federal customer data or can affect its confidentiality, integrity or availability, with location, boundary membership, encryption and CUI routing.Supplied with the Class A application; published as a restricted trust-center resource, no NDA, when that application is filed
SOC 2 Type II reportPDF (restricted use)Prescient Assurance LLC, issued 2026-08-31, Security Trust Services Criteria, period 2026-04-15 to 2026-07-15, unqualified opinion, no exceptions on 131 tested controls. This is the approved alternative security framework assessment that Class A rests on (FRC-CLA-ASF). Independent verification and validation of the certification package by a FedRAMP Recognized independent assessment service is optional at Class A (FRC-CLA-IVV), and none is engaged for this submission. An independent assessor is engaged for the Class C assessment that follows. The management representation letter accompanying the report is retained in the evidence repository and supplied with the application and on request to fedramp@specset.com.Trust center (trust.specset.com), restricted resource, view only, no NDA — published today
SOC 2 Type II engagement documentationPDF (restricted use)Verified engagement documentation for the completed examination, dated 2026-08-25. The next report is planned after the 2026-07-16 to 2027-07-15 period ends and before 2027-08-31. The renewal engagement letter for that period is signed by the assessor; the client signature is pending. Gap: no assessor bridge or gap letter covers 2026-07-16 to the application date. Plan: settle the bridge-letter position with the assessor before the application is filed, and supply the letter with the assessment materials if one is issued.Retained in the evidence repository; supplied with the Class A application and on request to fedramp@specset.com
Incident Response ProcedureMarkdown / PDFDetection, triage, FedRAMP reportability evaluation, initial and final incident reporting (IEC-CSO-EFR / IIR / OIR / FIR), and the FedRAMP Security Inbox procedure.Supplied with the Class A application; published as a restricted trust-center resource, no NDA, when that application is filed
Vulnerability Management ProcedureMarkdown / PDFPersistent detection (Dependabot security alerts and CodeQL code scanning on the application and infrastructure repositories, Artifact Registry image scanning of deployed digests), PAIN-based evaluation within 14 days, Class A remediation timeframes, and adoption of the VDR / VER rulesets ahead of the 2026-12-07 mandate.Supplied with the Class A application; published as a restricted trust-center resource, no NDA, when that application is filed
Security policiesPDF / webThe policy set maintained in Vanta, with employee acceptance recorded there: information security, access control, data management, cryptography, operations security (which carries the change management requirements), acceptable use, password, mobile device, data leakage prevention and third-party management policies, plus the incident response plan and the business continuity and disaster recovery plan. Gap: the revised business continuity and disaster recovery plan that aligns the recovery time objective with the recovery plan is pending approval, and the approved version still records the earlier objective. Plan: approve the revision by 2026-11-30, before the 2026-12-01 Ongoing Certification Report.Supplied with the Class A application; published as a restricted trust-center resource, no NDA, when that application is filed
Vulnerability activity reportsMarkdown + JSON, monthlyMonthly vulnerability detection and response activity (VER-TFR-MRH). First report 2026-10-01.Published as a restricted trust-center resource, no NDA, from 2026-10-01
Recovery planMarkdown / PDFThe recovery plan for the offering (KSI-RPL-ARP): service recovery objectives of RTO 24 elapsed hours and RPO 15 minutes (KSI-RPL-RRO), per-datastore backup and recovery procedures aligned to those objectives (KSI-RPL-ABO), and the recovery testing cadence (KSI-RPL-TRC). Delivered as supporting-evidence document 12, "Recovery and Backup Configuration".Supplied with the Class A application; published as a restricted trust-center resource, no NDA, when that application is filed
Training effectiveness review (KSI-CED-RAT)JSONFour-category review of security training effectiveness for all staff, completed 2026-09-12, with follow-up actions. Next review 2026-12-01.Supplied with the Class A application; published as a restricted trust-center resource, no NDA, when that application is filed
Incident register and simulated Final Incident ReportMarkdown + JSON (FedRAMP incident report schema)Incident register entries, the quarterly review record, and a simulated tabletop exercise with its reportability evaluation and schema-valid Final Incident Report.Supplied with the Class A application; published as a restricted trust-center resource, no NDA, when that application is filed
Class A supporting evidence documentsTwelve PDFs, each with its source exports as appendicesTwelve documents, one per artifact the Security Decision Record cites by name, so a reviewer opens exactly what the record points to: change management record; network boundary and Cloud Armor configuration; egress enforcement verification; identity and access configuration; staff authentication verification; training effectiveness review; incident response records; encryption and secrets configuration; vulnerability detection baseline and exception EX-2026-001; information resources inventory sources; assessment materials and schedule; and recovery and backup configuration. Each states the facts, the rule identifiers it evidences and its source records, with the machine-readable export appended.Supplied with the Class A application; published as a restricted trust-center resource, no NDA, when that application is filed
Service availability (CDS-CSO-AVR)Web page + JSONCurrent status, 90-day per-service history and incidents, hosted independently of the offering; machine-readable at https://status.specset.com/index.json.Public: https://status.specset.com
Secure configuration guidanceWeb pageCustomer-side configuration guidance (single sign-on, roles, CUI mode). The Secure Configuration Guide rules (SCG-CSO) apply to Classes B, C and D, not to Class A, so no guide is required for this application. Gap: not yet published. Plan: publish it on the Trust Center and link it from serviceProperties.secureConfigurationGuidance in this document before the Class C application.Not yet published
Trust Centerhttps://trust.specset.com
Access instructions: The landing page at https://trust.specset.com requires no login. FedRAMP staff and agency reviewers request access to the restricted FedRAMP Certification Data from the Trust Center page. Specset approves requests manually and does not require acceptance of terms or a non-disclosure agreement. If a request is not approved within one business day, email fedramp@specset.com.
Next Ongoing Certification Report Date2026-12-01
Third-Party Information Resources

FedRAMP Certified (8)

FedRAMP IDUse
FR1805751477Google Cloud Platform (Google Services) — primary hosting of all production infrastructure in project specset-prod-assured (Assured Workloads): GKE Autopilot, Cloud SQL, Cloud Storage, Memorystore, Cloud KMS, Cloud Load Balancing and Cloud Armor, Cloud Logging and Monitoring, Secret Manager, Artifact Registry, and Vertex AI (Gemini) model inference, embeddings and Web Grounding for Enterprise. Organizations in CUI mode use Vertex AI in the Assured Workloads project at location us only; other organizations use Vertex AI in a peer Google Cloud project, specbook-production, outside Assured Workloads. Stores and processes customer data. A third Google Cloud project, specbook-development, holds the development user-content buckets, development service identity and development vendor-key secrets; it sits outside Assured Workloads and inside the assessment scope because it shares integration credentials and software delivery with production. A founder-run project-clone tool can copy a production project's documents into that development environment for debugging, so development stores may hold customer content. Two further Google Cloud projects are inside the assessment scope and hold no customer content: specset-dataroom, an investor data room with no connection to the offering, and vanta-scanner, which holds the compliance scanner's federated identity and read-only custom roles outside the boundary project. Gap: the clone tool does not yet exclude the projects of organizations in CUI mode. Plan: block cloning of CUI-mode organizations in the tool and record the rule in the production-access procedure before the 2026-12-01 Ongoing Certification Report.
AGENCYAMAZONEWAWS US East/West — supporting services: Amazon SES (transactional email), Route 53 (DNS), S3 (CI build cache, CloudTrail audit logs, and a legacy database-backup bucket from the pre-2026 hosting platform), GuardDuty (threat detection), and Amazon Bedrock (Claude model inference in us-west-2, for organizations not in CUI mode; prompts may include customer document text).
F1209051525Azure Commercial Cloud — Azure OpenAI (GPT model inference for organizations not in CUI mode; prompts may include customer document text) and Microsoft Entra ID application registrations for customer 'Sign in with Microsoft' single sign-on. No customer data is stored on Azure.
F1206081364Google Workspace — provider identity (Cloud Identity) for staff access to production through Identity-Aware Proxy, with security-key or passkey 2-Step Verification enforced for all staff; staff email including the FedRAMP Security Inbox. No customer data.
FR1812058188GitHub Enterprise Cloud — source control and CI/CD for the application and infrastructure-as-code. Dependabot security alerts and CodeQL code scanning run on the application and infrastructure repositories, with Dependabot version updates on the infrastructure repository. Deploys to production through OpenID Connect workload identity federation. No customer data.
FR2525556241Vanta Trust Management Platform — continuous configuration monitoring of the production cloud accounts (read-only metadata), compliance evidence and policies, and the Specset Trust Center at trust.specset.com. No customer data.
FR1823447014Slack — operational alerting and change-notification channel for the provider (infrastructure change notifications, security alerts). Resource metadata only; no customer data.
FR2604643715Perplexity Enterprise and API Platform (FedRAMP Certified, Class B) — web search for AI features of organizations not in CUI mode. Receives model-generated search queries; customer documents are not sent. Never called for organizations in CUI mode: their web lookups run on Vertex AI Web Grounding for Enterprise inside the Google Cloud Assured Workloads project.

Not FedRAMP Certified (13)

ResourceUse
Anthropic API (Claude, direct)
Anthropic, PBC
Direct Claude model inference for a small set of models not served through Amazon Bedrock, selectable only by Specset administrators; prompts may include customer document text. Never enabled for organizations in CUI mode.
Intercom
Intercom, Inc.
In-app customer support chat for organizations not in CUI mode. Processes customer user contact details and support conversation content; no project documents. The messenger never loads for an organization in CUI mode and its memberships are never shared with Intercom.
Google Generative AI (AI Studio)
Google LLC
Gemini API path outside the Google Cloud FedRAMP boundary, used as the embedding provider for organizations not in CUI mode; prompts may include customer document text. Never used for organizations in CUI mode, whose embeddings run on Vertex AI in the Assured Workloads project. Retirement is planned before the Class C application.
Cloudflare Workers AI
Cloudflare, Inc.
Cloudflare AI Gateway and Workers AI for experimental open-model inference selectable by organizations not in CUI mode. Prompts may include customer document text, and inference runs in Cloudflare data centers worldwide. The gateway does not store prompt or completion payloads, and the per-organization CUI mode excludes it. Cloudflare also supplies the edge fronting for the Trust Center custom hostname (trust.specset.com) as part of Vanta's Trust Center service; that use carries no customer data. The Cloudflare for Government offering is not used.
NOAA / National Weather Service APIs
US National Oceanic and Atmospheric Administration (federal agency)
Public weather and tide data for project daily logs. Receives a project site's latitude and longitude only; forecasts and tide data are returned to the daily log. Nothing is stored at the service. A US federal government data service, not a cloud service offering.
Apryse
Apryse Software Inc. (formerly PDFTron Systems Inc.)
Document-processing software from one vendor, used two ways, both inside the boundary or in the user's browser. The server-side PDF library runs in the application and worker pods on customer documents, and the structured-output module it needs is downloaded from the vendor at container image build and pinned by SHA-256 checksum. The browser viewer runs under an offline OEM license key, so viewing makes no call to the vendor. No customer document data is sent to the vendor; the resource is in scope as a software-supply-chain dependency that affects document-processing availability and build integrity.
Autodesk Platform Services
Autodesk, Inc.
Optional customer-initiated integration to the customer's own Autodesk tenant through OAuth; the customer chooses and authorizes the data exchanged. Disabled for organizations in CUI mode. Not used unless a customer connects it. Gap: the application gate that stops an organization in CUI mode from connecting the integration, and makes an existing connection inert, is written and reviewed but not yet deployed, so CUI mode does not disable this integration today. Plan: deploy the gate before the paid federal pilot.
Procore
Procore Technologies, Inc.
Optional customer-initiated integration to the customer's own Procore tenant through OAuth; the customer chooses and authorizes the data exchanged. Disabled for organizations in CUI mode. Not used unless a customer connects it. Gap: the application gate that stops an organization in CUI mode from connecting the integration, and makes an existing connection inert, is written and reviewed but not yet deployed, so CUI mode does not disable this integration today. Plan: deploy the gate before the paid federal pilot.
Claude Code (Anthropic) — engineering assistant
Anthropic, PBC
Coding assistant used by the founders on operator laptops. It is in the assessment scope because what it reads can include federal customer data: production configuration, cluster state, metadata and application logs read as a dedicated read-only service account, and database rows read through a time-limited tunnel that a founder approves each session. What it reads is sent to the model provider. The service account holds reader roles only and has no write permission on production. Database reads use Cloud SQL IAM authentication with SELECT-only grants. Every tunnel start is recorded as an Admin Activity audit entry, and an alert fires if the account ever appears as the principal of a write. Gap: rows of organizations in CUI mode are not yet excluded from that read-only database role. Plan: enforce the exclusion with row-level security before the 2026-12-01 Ongoing Certification Report.
OpenAI Codex — engineering assistant
OpenAI
Coding assistant used by the founders on operator laptops. It is in the assessment scope under the same production-access protocol as Claude Code. It reads as the dedicated read-only service account with no write permission on production, and reads database rows only through the founder-approved, SELECT-only, time-limited tunnel. Every tunnel start is recorded as an Admin Activity audit entry, and an alert fires on any write. What it reads is sent to the model provider. The same planned exclusion of CUI-mode rows applies.
Firecrawl
Mendable Labs, Inc.
Two dependencies on one vendor. The hosted scraper reads public bid-portal pages for specification research and receives the page URL together with the extraction instructions the assistant's model wrote, which may derive from a user's conversation; no document, embedding or database row is sent. The vendor's PDF parser is a pinned software dependency that runs inside the boundary on customer PDFs, so no customer document reaches the vendor through it. Gap: the scrape tool is not gated on CUI mode, so an organization in CUI mode can reach this non-certified vendor. Plan: apply the integration CUI gate to the tool and its workflow activity before the 2026-12-01 Ongoing Certification Report.
CARTO basemaps
CARTO, Inc.
Browser-side raster map tiles for one dashboard panel, the closeout facility map. The vendor receives the visitor's IP address and the requested tile coordinates, which disclose the approximate location of a project facility; no project name, address, identifier or document is sent, and no server-side path to the vendor exists. Gap: those tile requests are not gated on CUI mode. Plan: self-host the tiles and remove the egress before the 2026-12-01 Ongoing Certification Report.
Customer single sign-on identity providers (Google Sign-In and customer-configured OpenID Connect providers)
The customer's own identity provider (Google Sign-In, or any OpenID Connect provider a customer configures)
Customer-chosen authentication for customer users. Specset receives the identity assertion and the claims the customer's provider releases; no project document or row leaves the boundary. Each provider is the customer's own information resource under the customer's own administration, so its certification status is the customer's decision. Corporate Google single sign-on is enforced for Specset staff and superadmin access.
FedRAMP Recognized Independent AssessorNot applicable — Class A rests on an approved alternative security framework assessment (FRC-CLA-ASF) and independent verification and validation of the package is optional at Class A (FRC-CLA-IVV); an assessor is engaged for the Class C assessment, scheduled well inside the 24 months MKT-IIP-DLA allows from initial listing

Package metadata

Accountable officialGordon Hempton, CEO and Co-Founder · gordon@specset.com
Version2026.09.14
Last updated2026-09-14T04:30:00Z
Source of updategithub.com/specsetai/fedramp-marketplace (main branch; schema-validated by the repository's validate workflow; published to specset.com/fedramp/)