Compliance
Federal agencies can only use cloud services that have achieved FedRAMP authorization. AI systems sold to federal buyers must run entirely within FedRAMP-authorized environments, typically AWS GovCloud, Azure Government, or Google Cloud for Government. The commercial OpenAI API, Anthropic API, and most consumer AI products are not FedRAMP authorized and cannot legally receive federal government data.
We design and build AI systems that operate within FedRAMP authorization boundaries. Every architecture decision: LLM selection, vector database, logging pipeline, authentication — is made with the FedRAMP boundary in mind. We produce the SSP technical documentation your ISSO needs and implement the controls your AO will test.
Tell us what you're building.
FedRAMP applies NIST SP 800-53 control baselines to cloud systems used by federal agencies. These are the controls with the highest impact on AI system architecture.
All AI infrastructure must run within a FedRAMP Moderate or High authorized cloud environment. FedRAMP Moderate covers data classified up to CUI (Controlled Unclassified Information). FedRAMP High is required for data that, if disclosed, could cause severe damage to national security. Most civilian agency AI workloads fall under Moderate; DoD and intelligence community workloads typically require High or IL4/IL5.
Most commercial LLMs are not FedRAMP authorized. As of 2025, the primary authorized options are Azure OpenAI Service on Azure Government (FedRAMP High authorized), AWS Bedrock on AWS GovCloud (FedRAMP High authorized), and select open-weight models deployed on FedRAMP-authorized infrastructure. Standard commercial API endpoints for OpenAI, Anthropic, and Google are not FedRAMP authorized and cannot receive government data.
All government data must remain within the continental United States. No routing through non-US datacenters, no CDN nodes outside the US, no third-party services with overseas data processing. FedRAMP-authorized cloud regions are all US-based, but this must be verified for every service used, including logging, monitoring, and CDN layers.
FIPS 140-2 validated encryption for all data at rest and in transit. PIV/CAC authentication support for government user accounts (required for most agency deployments). Audit logging aligned to NIST SP 800-53 AU control family: specific log fields, retention periods (minimum 3 years), and tamper-evident storage are required by most agency ATOs.
FedRAMP requires ongoing continuous monitoring (ConMon) after authorization: monthly automated vulnerability scans, annual penetration tests, and monthly reporting to FedRAMP PMO and agency customers. AI systems add complexity: model versions must be tracked as configuration items, and output anomaly detection must integrate with the SIEM feeding your ConMon reports.
These are the specific deliverables for FedRAMP-ready AI systems. Each one corresponds to a control family in the NIST SP 800-53 baseline that auditors will test.
Full system design that keeps every component within the FedRAMP authorization boundary: compute, storage, LLM endpoints, logging, and monitoring. We document the system boundary and data flow for inclusion in your System Security Plan (SSP), which is the core document for ATO.
Configuration and deployment of LLM inference within FedRAMP-authorized cloud environments. Azure OpenAI Service on Azure Government and AWS Bedrock on GovCloud are the primary options. We configure the endpoints, set up private networking to avoid public internet routing, and document the configuration for auditors.
Application-level encryption using FIPS 140-2 validated cryptographic modules, required for most FedRAMP Moderate and all FedRAMP High systems. This covers the AI inference pipeline, vector databases, and any storage layer holding government data. We select FIPS-compliant libraries and document module validation certificates.
Structured audit logging for all AI interactions with the specific fields required by NIST SP 800-53 AU-2 and AU-3: event type, timestamp, user identity, source IP, object accessed, action taken, and outcome. Logs forwarded to your agency-approved SIEM (Splunk, IBM QRadar, or equivalent) in the format required for ConMon reporting.
We produce the AI-specific sections of your System Security Plan: system description, data flow diagrams, control implementation statements for AI-related controls, and the configuration baseline. Your AO (Authorizing Official) and ISSO review the full SSP; we produce the technical content for the AI components.
These are the authorized cloud environments and AI services we use for government deployments. Verify current authorization scope and impact level on the FedRAMP Marketplace before committing to a stack.
Important: Commercial API endpoints for OpenAI, Anthropic, and Google are NOT FedRAMP authorized. Do not route federal data through commercial endpoints.
FedRAMP High authorized on Azure Government. GPT-4 models available. Requires Azure Government subscription and enterprise agreement.
FedRAMP High authorized on AWS GovCloud (US). Claude, Llama 2, and Titan models available in GovCloud regions.
FedRAMP High authorized. Compute, storage, and networking for the full AI infrastructure stack.
FedRAMP High authorized. Full Azure service suite with US-only data residency guarantees.
FedRAMP Moderate and High authorized depending on region and service. Vertex AI availability in government regions is more limited than Azure and AWS, verify current scope.
FedRAMP AI work has a specific and demanding profile. We are direct about when it is the wrong fit.
Teams targeting state or local government only
FedRAMP is a federal programme. It covers US federal agencies. State and local governments may reference FedRAMP as a purchasing signal, but they are not bound by it. If your target customers are state or municipal agencies without a federal mandate, StateRAMP (a separate programme) or a simpler compliance posture may be more appropriate.
Early-stage startups without budget for the required infrastructure
FedRAMP-authorized cloud environments and the engineering overhead of FIPS-compliant deployments cost significantly more than standard commercial cloud. AWS GovCloud and Azure Government carry higher base costs than commercial equivalents, and the minimum ATO process runs 6–18 months. This is not the right starting point for a pre-revenue product.
Teams expecting us to manage the full ATO process
An Authority to Operate (ATO) is issued by a federal agency's Authorizing Official after a full security assessment. We produce the AI-specific technical documentation and implement the controls, but the ATO process involves your agency customer, a 3PAO (Third Party Assessment Organization), and the FedRAMP PMO. We are one input into that process, not the owner of it.