Trust Center: CMMC, FedRAMP, and Data Security
How Movegistics AI protects your data and meets the standards the moving and defense communities expect.
Last updated: June 22, 2026
Who operates Movegistics AI.
Netensity Corporation, a California C-Corp founded in 2010, operates the Movegistics AI platform. HelixIQ, Inc., a Delaware corporation founded by the same principal, operates HomeSurvey.ai and holds the AI computer vision pipeline IP. The two entities are bound by inter-company agreements governing IP licensing and operational coordination, and operate from separate AWS accounts.
Sixteen years on AWS, built for the long haul.
Movegistics AI has operated on Amazon Web Services for more than 16 years, running in U.S. regions on AWS commercial infrastructure. Customer data is held in encrypted, managed AWS data stores and object storage, with no offshore handling of military-move data.
Production runs in U.S. AWS regions. Data for military moves is stored and processed in the United States.
How your data is protected, end to end.
All data is encrypted in transit using TLS 1.3.
Customer data is encrypted at rest with AES-256 across managed databases and object storage on AWS.
Data for military moves is stored in the United States.
Survey media is retained only as long as operationally needed, with a short target purge window for military shipments. Retention is configurable per program.
When a shipment is designated as a military or GSA move, it is flagged at intake so CUI-relevant data is handled with the appropriate controls. This supports proper handling and the path to Level 2.
CMMC Level 1 affirmed; FedRAMP on the roadmap.
Netensity Corporation has completed the CMMC Level 1 self-assessment and affirmed MET status for every security requirement in FAR clause 52.204-21(b)(1), registered in SPRS through PIEE. This supports moving companies and Transportation Service Providers operating under the 2026 DP3 Household Goods Tender of Service, where CMMC Level 1 affirmation is required to handle Federal Contract Information (FCI).
“We do not present Level 1 as authorization to handle CUI.”
Today Movegistics AI, operated by Netensity Corporation, is CMMC Level 1 affirmed, covering Federal Contract Information (FCI). Our next stage is CMMC Level 2, the level that governs Controlled Unclassified Information (CUI): for CUI workloads we are moving to AWS GovCloud, a FedRAMP-authorized environment that provides the controlled foundation Level 2 requires. Application-level FedRAMP authorization builds on that GovCloud foundation and is pursued in step with our Level 2 work.
Recognized by the International Association of Movers, the largest trade association in global relocation.
An IAM Trusted Supplier in good standing, recognizing members that invest in competence, knowledge, and conscientiousness, and demonstrate a tangible commitment to trustworthiness with their industry partners.
IAMX Validated, IAM's independent business validation.
A Premier-level member of the International Association of Movers.
Official IAM-issued ITS badge, shown at protected size: minimum 14 mm height with clear space equal to the height of the “S.” Not sheared, skewed, rotated, or recolored.
Verify in IAM Mobility ExchangeThe third parties that help us run the service.
We use a limited set of vetted sub-processors to operate Movegistics AI. Each is engaged under terms that require appropriate protection of customer data.
| Sub-processor | Purpose |
|---|---|
| Amazon Web Services | Cloud infrastructure, data storage, and processing (U.S. regions) |
| Amazon SES | Transactional and notification email |
| Twilio | SMS delivery (e.g., sending the survey link to the customer) |
| Stripe | Payment processing |
| Remedy | Payment processing |
| QuickBooks Online | Accounting sync (billing data; does not touch survey media) |
| Zendesk | Customer support ticketing and help center |
E-signature is built natively into the platform — no third-party signing processor is used. Marketing email is handled separately and is not connected to customer survey or CRM data.
If something goes wrong, here is our process.
Movegistics AI maintains a documented incident response plan. In the event of a security incident affecting customer data, we move through containment, root-cause analysis, customer notification, and remediation.
Customers are notified without undue delay of any incident that materially impacts their data, with timeline commitments aligned to applicable contractual and regulatory requirements.
Your data, handled with care.
We collect and process only the data needed to operate the platform, and we make our policies and agreements available for review.
Official sources, so you can verify everything yourself.
Need documentation for your vendor file?
Questions about our security or compliance posture? We'll respond promptly with what you need for your records.
