Security and FedRAMP High Authorized



Security and Compliance

Federal-grade security from the first login.

FedRAMP® High Authorized (Class D). Hosted in AWS GovCloud (US), operated with a FedRAMP-authorized infrastructure partner, and independently assessed by an accredited third-party assessment organization.

FedRAMP High Authorized (Class D) badge

The stack

Four layers of responsibility. Each one assessed.

Your System Security Plan describes how you protect Controlled Unclassified Information. This is what sits between that document and the rest of the internet.

Fig. 01 · Trust stack

Cross-section view

01

Your compliance data

System Security Plans, POA&M entries, control evidence, assessment artifacts, and the audit trail behind every change.

SSPPOA&MEvidenceAudit trail
02

FutureFeed

Application-layer controls: role-based access, multi-factor authentication, tenant separation, defined Hawk AIâ„¢ data boundaries, and an immutable activity log.

AES-256 at restTLS 1.2+ in transitMFARole-based access
03

Project Hosts

Infrastructure operator. Patching, vulnerability scanning, log review, monitoring, and incident response against the federal control baseline.

FedRAMP-authorized CSPContinuous monitoring
04

AWS GovCloud (US)

Isolated federal cloud region, authorized for DoD Impact Levels 2, 4, and 5. Operated by U.S. persons on U.S. soil. FutureFeed migrated all application code and data here in 2021.

U.S. personsU.S. soilIL2 / IL4 / IL5

Read top to bottom. Each layer inherits the controls of the layer beneath it, and each layer is in assessment scope.

FedRAMP High Authorized (Class D) badge

FutureFeed is FedRAMP High Authorized (Class D). The Authority to Operate is granted, not in process. Under the 2026 Consolidated Rules, Class D is the designation that replaces the FedRAMP High baseline, and it remains the most rigorous of the four certification classes.

Continuous, not a certificate

Automated vulnerability scanning, log review, access certification, and annual independent reassessment keep the authorization in force year over year. A point-in-time report is not the deliverable. The operating posture is.

Evidence for your procurement team

The certification package, the most recent security assessment report, and the continuous-monitoring summary are available to prospective customers under NDA. Your security reviewer gets documents, not adjectives.

Written into your own scope

When an assessor asks which external service providers are in your CMMC boundary, the answer needs a paper trail. Our authorization documentation is built to be cited directly in your System Security Plan.

FedRAMP details request

Request the package.

Access to the authorization package is requested through FedRAMP directly. Use the request form below and follow the instructions at the top of the document.

FedRAMP® is a registered mark of the U.S. General Services Administration. The FedRAMP name and logo are the property of the GSA. Reference to the FedRAMP Marketplace is provided for verification purposes and does not imply endorsement.