Skip to content
Security & compliance · Built for high-stakes projects

Security that shows its work.

Your project record can contain pricing, protected facility details, and the decisions that govern the work. Specset protects that record from upload through inference, and publishes the evidence procurement teams need to verify it.

Assurance file · SCP-01
Current public posture

Specset Cloud Platform

Published
SOC 2 Type II
Report issued Aug 2026
NIST SP 800-171
CMMC L2 · self-assessed
FedRAMP 20x
Class A in progress
Access controls
MFA · RBAC
Model training
Customer data excluded
Public claims link to a report, record, or policy. Protected evidence is available through the Trust Center.
SOC 2 Type IIReport issued August 2026
NIST 800-171CMMC L2 · self-assessed
FedRAMP 20xClass A in progress
01 · Data flow

Know where the record goes.

Specset narrows every step to the data needed for the job. Files remain part of your protected project record. Model providers receive scoped context for inference, not a corpus to train on.

02 · Controls

Controls that survive the questionnaire.

The answers procurement asks for most are not promises on a sales slide. They are operating controls, independently examined and supported by evidence.

Control 01

Encryption

Customer data is encrypted in transit with TLS 1.2 or later and at rest with AES-256 encryption.

Control 02

Identity & access

Multi-factor authentication, role-based access control, least-privilege practices, and access logging govern production access.

Control 03

Operations

Change management, incident response, vendor security review, and control monitoring sit inside the audited security program.

Control 04

Data ownership

You retain ownership of uploaded documents and project data. Specset uses them only to operate and improve the service.

Control 05

Data lifecycle

Project data is retained only as needed to provide the service and meet legal obligations. Deletion requests go directly to our team.

Control 06

Independent evidence

Detailed security documentation and assurance reports are available through the Specset Trust Center, with protected reports available by request.

03 · AI & your data

Your project is context, never training material.

Specset uses approved large-language-model APIs to analyze project documents. We send the context needed to perform the requested work. Your content is not used to train third-party models.

You keep ownership of uploaded content. Our use is limited to operating and improving the service, subject to the agreements and controls that govern your account.

Read the AI data policy →
Inference contractPer request
  1. 01
    Scope

    Retrieve the relevant project context for the requested task.

  2. 02
    Protect

    Transmit over encrypted channels to an approved provider.

  3. 03
    Answer

    Return the result with project citations for human verification.

  4. 04
    Exclude

    Do not use customer content to train the provider's models.

04 · Government deployment

A separate lane for controlled work.

SpecGov is a separate government instance for projects with controlled-data requirements. Model inference is pinned to the defined boundary with no fallback outside it. Analytics and public-site widgets stay out.

Security requirements vary by agency, contract, and data type. Our security team will map the deployment and evidence to your specific requirements before data is introduced.

Review your requirements →
SpecGov · boundary viewRestricted
U.S. government deployment
Defined security boundary
SpecGovProject record · Agents · Model inference
Unapproved third-party egressBlocked
Fig. 02 · Separate deployment with inference constrained to the defined boundary
05 · FedRAMP

The listing is public. The status is precise.

Specset Cloud Platform is listed in the official FedRAMP Marketplace. We are pursuing FedRAMP 20x Class A certification; the listing is in Initial Implementation and no class has been granted yet.

Federal and public work →
Official marketplace record20x · In progress
Cloud service offering
Specset Cloud Platform
Marketplace ID
FR2631258135
Current class
Not yet certified — Initial Implementation
Next milestone
Class A certification (in progress)
Certification status
Class A application filed September 2026, under review
Verify on FedRAMP.gov →
Common questions

What teams ask about security.

01Has Specset completed a SOC 2 Type II examination?

The SOC 2 Type II report was issued in August 2026 to Spot.xyz Corporation DBA Specset. Protected reports are available by request through the Trust Center at https://trust.specset.com.

02Is customer data used for model training?

No. Specset uses approved large-language-model APIs to analyze project documents and sends the context needed to perform the requested work. Your content is not used to train third-party models. Customer content is excluded from model training.

03How does Specset encrypt data and control access?

Customer data is encrypted in transit with TLS 1.2 or later and at rest with AES-256 encryption. Multi-factor authentication, role-based access control, least-privilege practices, and access logging govern production access.

04What is Specset's FedRAMP 20x Class A status?

No class has been granted yet. Specset Cloud Platform is listed in the FedRAMP Marketplace (FR2631258135) in Initial Implementation. Specset is pursuing FedRAMP 20x Class A certification. The Class A application was filed in September 2026 and is under FedRAMP review. The public package is at https://www.specset.com/fedramp.

05What is SpecGov?

SpecGov is a separate government instance for projects with controlled-data requirements. Model inference is pinned to the defined boundary with no fallback outside it. Analytics and public-site widgets stay out. Security requirements vary by agency, contract, and data type. Our security team will map the deployment and evidence to your specific requirements before data is introduced. Write to security@specset.com.

06How do I request security evidence or Trust Center access?

The Trust Center at https://trust.specset.com has the security posture, control monitoring, and protected reports available by request. Send questionnaires and evidence requests to security@specset.com.

07How do I report a security vulnerability?

Read the vulnerability disclosure policy at https://www.specset.com/security/vulnerability-disclosure.

Bring the questionnaire

Let security talk to security.

Send your data-flow questions, control matrix, or agency requirements directly to the team that owns the answers.

Found a security issue? Read the vulnerability disclosure policy →