WorkbenchLearnBook a Build with AI session →
frwrd.team

What happens to your data.

You hand us past performance, pricing, and pursuit strategy — sometimes controlled information on top of that. Handling it right is part of what makes a bid defensible: no CUI leaked, no data trained on, every claim traceable to a source you can stand behind in an audit. We're not an AI company. We run on AWS Bedrock, where the model providers can't train on your data, and we keep each client separated down to the AWS account. Here's what that means for your material.

How we handle your data

Least privilege, no training

Scoped, publishable keys on the client side; privileged credentials never exposed. MFA and access reviews. Your material is never used to train models— that's a contract term, not a hope.

Per-client, delete-on-exit

Each engagement is isolated. We minimize and redact before anything reaches a model, hold to retention limits, and delete on exit. On exit you choose: delete it, or take it with you — we hand over the keys to the infrastructure and you do what you want with it.

An NDA before anything moves

We sign a mutual NDA and a data-handling addendum before sensitive material changes hands. Classified and ITAR-controlled material never comes onto our systems — that work happens inside your environment, under your controls.

Every agent action is logged. You can see what that discipline produces in the public sample Replay readout. You get provenance for your proposal and a clean record of who did what — the volume runs under a named human who owns the call.

Regulated and CUI bids

handled safely

For Controlled Unclassified Information you don't need servers or a SCIF. There are two ways to keep your regulated bid safe, and we'll tell you which one fits yours. Controlled work is priced per engagement.

We work inside your boundary

If you already run an accredited environment, like a GCC High tenant or your own managed devices, we work inside it. Your data never leaves your boundary, and your accreditation covers the work.

We build on authorized services

When you don't have your own environment, we set one up on AWS GovCloud + Bedrock, where Claude is authorized at FedRAMP High and DoD IL4/5. Those authorizations are building blocks — your organization still owns the authorization of the system that uses them, and we design to make that straightforward.

US-persons, hardened endpoints

US-persons handling, a locked-down workstation, and CUI marked and isolated end to end. Least-privilege access and an audit log throughout. For ITAR programs we work inside your environment when it supports that work — you remain the authority on what your export-control obligations allow.

A human-only mode

If your bid requires no AI at all, we run it human-only. The people and the process don't change; the agents step out.

Have a bid with controlled information?

Tell us what you're holding and where it has to live. We'll tell you whether we work inside your environment, stand up an enclave, or aren't the right fit.

Book a call →