Security and Compliance
Federal-grade security from the first login.
FedRAMP® High Authorized (Class D). Hosted in AWS GovCloud (US), operated with a FedRAMP-authorized infrastructure partner, and independently assessed by an accredited third-party assessment organization.
The stack
Four layers of responsibility. Each one assessed.
Your System Security Plan describes how you protect Controlled Unclassified Information. This is what sits between that document and the rest of the internet.
Your compliance data
System Security Plans, POA&M entries, control evidence, assessment artifacts, and the audit trail behind every change.
FutureFeed
Application-layer controls: role-based access, multi-factor authentication, tenant separation, defined Hawk AIâ„¢ data boundaries, and an immutable activity log.
Project Hosts
Infrastructure operator. Patching, vulnerability scanning, log review, monitoring, and incident response against the federal control baseline.
AWS GovCloud (US)
Isolated federal cloud region, authorized for DoD Impact Levels 2, 4, and 5. Operated by U.S. persons on U.S. soil. FutureFeed migrated all application code and data here in 2021.
Read top to bottom. Each layer inherits the controls of the layer beneath it, and each layer is in assessment scope.
FutureFeed is FedRAMP High Authorized (Class D). The Authority to Operate is granted, not in process. Under the 2026 Consolidated Rules, Class D is the designation that replaces the FedRAMP High baseline, and it remains the most rigorous of the four certification classes.
Continuous, not a certificate
Automated vulnerability scanning, log review, access certification, and annual independent reassessment keep the authorization in force year over year. A point-in-time report is not the deliverable. The operating posture is.
Evidence for your procurement team
The certification package, the most recent security assessment report, and the continuous-monitoring summary are available to prospective customers under NDA. Your security reviewer gets documents, not adjectives.
Written into your own scope
When an assessor asks which external service providers are in your CMMC boundary, the answer needs a paper trail. Our authorization documentation is built to be cited directly in your System Security Plan.
FedRAMP details request
Request the package.
Access to the authorization package is requested through FedRAMP directly. Use the request form below and follow the instructions at the top of the document.
Step one
FedRAMP Package Access Request Form
A PDF hosted by FedRAMP. Follow the instructions at the top of the document before submitting.
Step two
GSS One - AWS, FedRAMP Marketplace
The information required to populate the request form is published on this Marketplace listing.
FedRAMP® is a registered mark of the U.S. General Services Administration. The FedRAMP name and logo are the property of the GSA. Reference to the FedRAMP Marketplace is provided for verification purposes and does not imply endorsement.