docs/main/security-guide/compliance-frameworks/index.mdx
This section is the canonical home for framework-specific compliance documentation: FedRAMP, DoD IL4/IL5, DISA STIG, FIPS, HIPAA, FINRA, CMMC, and others. Each page below documents Mattermost's authorization posture, the configuration required to align with the framework, and (where applicable) the mapping from framework controls to specific Mattermost features and settings.
:::note Operational vs. framework content Compliance is documented in two places by design:
Cross-link both ways when adding new content. :::
Each framework page leads with an <AttestationStatus> badge stating Mattermost's current authorization posture (Authorized / In Process / Roadmap / Not Pursued). Pages with "In Process" or "Roadmap" status document the gap honestly — what controls are met today, what's not, and the expected timeline.
For legally citable attestation letters, see the Mattermost Trust Portal (external). The pages in this section describe configuration and control mappings — they do not substitute for the formal attestation artifacts.