Shared Responsibility Matrix
One table, every responsibility the platform touches, exactly one owner per cell. GCH = GovConHouse. You = the customer’s organization (and its signing officials).
| Responsibility | GCH | You | Government | Assessor |
|---|---|---|---|---|
| Hold certifications for the platform itself | No (holds none) | No | n/a | n/a |
| Hold YOUR certifications (CMMC/FedRAMP/etc.) | No | Yes | n/a | n/a |
| Compute CMMC control status from your evidence | Yes | No | n/a | n/a |
| Verify that your evidence is true | No | Yes | n/a | Yes |
| Keep your compliance data separate from other customers’ | Yes | No | n/a | n/a |
| Compute your SPRS score (DoD methodology) | Yes | No | n/a | n/a |
| Affirm and submit your SPRS score | No | Yes | Receives | n/a |
| Draft SSP/POA&M/SAP/SAR/ATO package documents | Yes | No | n/a | n/a |
| Complete and validate the SSP narrative | No | Yes | n/a | May review |
| Grant an Authority to Operate | No | No | Yes | n/a |
| Perform the security assessment | No | No | n/a | Yes |
| Decide what is CUI and its categories | Assists | Yes | Defines | n/a |
| Encrypt CUI fields and uploaded evidence at rest | When the keys are set (see note) | Set the keys on self-host | n/a | n/a |
| Encrypt connections (in transit) | Yes | No | n/a | n/a |
| Decide what to upload (including any CUI) | No | Yes | n/a | n/a |
| Keep FAR/DFARS clause citations real in generated text | Yes (checked against the clause catalog) | No | n/a | n/a |
| Review generated proposals before they go anywhere | No | Yes | n/a | n/a |
| Flag risky passages in solicitation text | Yes | No | n/a | n/a |
| Report security incidents to the government | No | Yes | Receives | n/a |
| Sign flow-down clauses to your subcontractors | No | Yes | n/a | n/a |
| Make ITAR/export-control determinations | No (screens only) | Yes | Regulates | n/a |
| Back up the platform’s own infrastructure | Yes (hosted); operator (self-host) | No | n/a | n/a |
| Keep the immutable audit trail | Yes | No | n/a | n/a |
Encryption at rest, exactly
Section titled “Encryption at rest, exactly”Two keys, two scopes, both free and open source:
- Uploaded evidence files are encrypted at rest with Fernet when the
operator sets
FERNET_KEY. Files written before the key existed stay readable (they are plaintext, and the platform does not pretend otherwise). Generate a key withpython -c "from cryptography.fernet import Fernet; print(Fernet.generate_key().decode())". - CUI-marked contract fields are encrypted at the application layer
when
CUI_ENCRYPTION_KEYis set (64-char hex). Without the key, fields store plaintext and the platform logs that state.
When a key is not set, the platform stores plaintext and says so. It never claims encryption it did not perform.
The two sentences that matter
Section titled “The two sentences that matter”- GovConHouse prepares, computes, logs, encrypts, and labels. It never signs, submits, or certifies anything on your behalf.
- You review, sign, and submit. The government, or its recognized assessor, evaluates.
Full version with notes and mechanism references for every row lives in
the repository at docs/audits/SHARED_RESPONSIBILITY_MATRIX_2026-09-29.md.