Skip to main content
Common Criteria (CC) coverage:
CriterionAGCMS feature
CC6.1 — Logical accessSSO via WorkOS, MFA, scoped API keys
CC6.7 — Restricted system accessRLS-isolated tenant data, RBAC
CC7.2 — System monitoringPrometheus /metrics, Grafana dashboards
CC7.3 — Security event responseAlerts page workflow with SLA timers
CC7.4 — Vulnerability managementDaily dependency scans, quarterly pen-tests
CC8.1 — Change managementPolicy versions, audit-logged config changes
AGCMS is in observation period with Vanta. The Type II report is targeted for Q3 2026 and will be available on request.