Encryption
Customer data is encrypted in transit with TLS 1.2 or later and at rest with AES-256 encryption.
Your project record can contain pricing, protected facility details, and the decisions that govern the work. Specset protects that record from upload through inference, and publishes the evidence procurement teams need to verify it.
Specset narrows every step to the data needed for the job. Files remain part of your protected project record. Model providers receive scoped context for inference, not a corpus to train on.
The answers procurement asks for most are not promises on a sales slide. They are operating controls, independently examined and supported by evidence.
Customer data is encrypted in transit with TLS 1.2 or later and at rest with AES-256 encryption.
Multi-factor authentication, role-based access control, least-privilege practices, and access logging govern production access.
Change management, incident response, vendor security review, and control monitoring sit inside the audited security program.
You retain ownership of uploaded documents and project data. Specset uses them only to operate and improve the service.
Project data is retained only as needed to provide the service and meet legal obligations. Deletion requests go directly to our team.
Detailed security documentation and assurance reports are available through the Specset Trust Center, with protected reports available by request.
Specset uses approved large-language-model APIs to analyze project documents. We send the context needed to perform the requested work. Your content is not used to train third-party models.
You keep ownership of uploaded content. Our use is limited to operating and improving the service, subject to the agreements and controls that govern your account.
Read the AI data policy →Retrieve the relevant project context for the requested task.
Transmit over encrypted channels to an approved provider.
Return the result with project citations for human verification.
Do not use customer content to train the provider's models.
SpecGov is a separate government instance for projects with controlled-data requirements. Model inference is pinned to the defined boundary with no fallback outside it. Analytics and public-site widgets stay out.
Security requirements vary by agency, contract, and data type. Our security team will map the deployment and evidence to your specific requirements before data is introduced.
Review your requirements →Specset Cloud Platform is listed in the official FedRAMP Marketplace at Class A, with Class C certification in progress.
Public posture, protected reports, legal terms, and a direct line to the people who own the controls.
Security posture, control monitoring, and protected reports available by request.
Open Trust Center →02 · FederalIndependent program listing, current phase, deployment model, and public contacts.
Verify the listing →03 · LegalHow information is collected, used, protected, retained, and governed.
Read the policies →Send your data-flow questions, control matrix, or agency requirements directly to the team that owns the answers.