Federal-grade data handling with a citation trail you can hand back.
Platform posture
FedRAMP-aligned hosting, engineered for federal data.
We treat your procurement and rulemaking data as sensitive by default. The platform runs on FedRAMP-aligned infrastructure with the controls federal programs expect, so you can deploy Tributary inside an existing federal review pipeline without a separate security review for the underlying host.
Encryption at rest
All customer data is encrypted at rest using AES-256 disk-level encryption, with managed key rotation handled by the underlying FedRAMP-aligned cloud.
Encryption in transit
All client and inter-service traffic is encrypted in transit using TLS 1.2+ with a modern, AEAD cipher suite and HSTS on every public endpoint.
Role-based access control
Least-privilege access via better-auth with per-workspace roles (owner, contributor, viewer, auditor). Every read and write is authorized against the caller’s userId + role, never a shared credential.
Audit logging
Immutable, append-only audit log capturing timestamp, actor, action, and target object. Logs are exportable for review and retained for the same window as your data.
Citation trail
Every deliverable links back to a primary federal source.
A draft is only as good as its sources. Tributary writes against the authoritative federal record and stamps every line with a citation back to the source document. The same trail is what makes an export FOIA-ready — your officer hands back a document whose citations already resolve to a primary source, not a re-typed summary.
SAM.gov
Solicitation metadata, attachments, amendments, and award notices → linked to the SAM.gov opportunity ID with canonical URL preserved verbatim.
Federal Register
Proposed rules, final rules, notices, and public comments → linked to the document’s Federal Register page and paragraph anchor where available.
Congress.gov
Bills, resolutions, committee record, and the Congressional Record → linked to the Congress.gov bill ID or Record page that the line was drawn from.
Data handling
Where your data lives, how long we keep it, and who else sees it.
Federal buyers ask three questions: where is the data, how long is it kept, and who besides us touches it. The answers are below in plain language.
Data residency
Customer data is stored in US-only regions by default. GCC-High is available on the Enterprise plan for organizations that require it.
Retention window
Project data and audit logs are retained for 30 months, aligned to the SAM.gov archive horizon for federal procurement records. Longer windows are available on Enterprise.
No model training on customer inputs
Your inputs and your drafts are never used to train third-party models. Inference is isolated through the platform proxy and runs only against the model you selected for that workflow.
Third-party subprocessors
Hosting (FedRAMP-aligned cloud), email delivery, payment processing, object storage, and uptime monitoring. The full subprocessor list, with current vendors, is available on request.
Security packet
Request our security packet.
Want the full packet? FedRAMP-aligned architecture diagram, SIG-lite questionnaire, and subprocessor list under NDA.
Send a note and we'll reply with the documents plus a named security reviewer on the first reply — usually within one business day.
Submissions route into a private intake queue. We do not share security-review traffic with mailing lists, ad networks, or third-party subprocessors outside of the hosting + delivery stack disclosed above.