Government tier — PIV-CAC, FIPS, agency pivot
The Government tier is the canonical procurement path for federal civilian agencies. It is contract-only and sales-led. The agency-pivoted layout, extended audit retention, and export watermarking are live in the product today. PIV-CAC authentication, FIPS-validated cryptography, and AWS GovCloud residency are on the Government-tier delivery roadmap — they are scoped and completed jointly with your agency during onboarding. Ask us for current status on any item below.
What's different
| Capability | Government tier |
|---|---|
| Authentication | OIDC/SAML on the Government-tier delivery roadmap (set up jointly with your agency during onboarding); PIV-CAC follows |
| Cryptography | AES-256 at rest; TLS 1.3 in transit; FIPS 140-3 validated modules are a deployment option scoped per agency (roadmap) |
| Data residency | AWS GovCloud (US-Gov-East-1 primary, US-Gov-West-1 backup) — deployment option scoped per agency (roadmap) |
| Layout | Agency-pivoted: watched agency lives at the top of every view; Brief retrieval constrains to that agency |
| Audit log | 7-year retention; self-service export to a customer-owned S3 bucket of record (GovCloud bucket configured during onboarding) |
| Compliance posture | FedRAMP-aligned control baseline today — SOC 2 Type II in progress plus a NIST 800-53 Moderate self-attested SSP; we pursue formal FedRAMP authorization with our first agency sponsor |
| Watermarking | Every exported Brief, share link, and DOCX carries a per-user, per-session watermark |
| Contracting vehicle | Custom MSA or agency-specific BPA; a GSA Schedule listing is planned — ask sales for current vehicle options; security documentation provided |
PIV-CAC setup
PIV-CAC authentication is on the Government-tier delivery roadmap; it is not live in the product today. During onboarding we register your agency's PIV issuer (typically a civilian CA) with the workspace OIDC bridge and complete card-present login jointly with your agency's identity team — including reader compatibility testing against the hardware your agency actually issues. We do not certify specific reader models in advance.
OIDC and SAML sign-in are on the Government-tier delivery roadmap and are stood up jointly with your agency during onboarding — they are not self-service in the product today. Your agency decides at onboarding whether PIV-CAC becomes the required path once delivered or whether OIDC/SAML remains a sanctioned fallback (e.g., for tablets without card readers).
FIPS mode
FIPS-validated cryptography is a Government-tier deployment option scoped per agency during onboarding; the application-layer enforcement exists today, and the validated-module deployment is on the roadmap. When provisioned, FIPS mode is locked as a workspace property — disabling it is not supported — and embeddings, retrieval, and synthesis are routed through FIPS-validated cryptographic endpoints. AI-provider routing for FIPS deployments is scoped as part of the same onboarding engagement.
Agency pivot
The agency-pivot layout collapses the persona switcher and pins the watched agency at the top of /today, /radar/forecast, /network, and /search. Retrieval for the Brief constrains to passages whose entity-graph tags include that agency. Other agencies remain visible in the network graph but do not appear in the synthesized prose.
Procurement
Government tier purchases run through an open-market MSA or an agency-specific BPA; a GSA Schedule listing is planned. Sales engineering provides the security documentation package — the NIST 800-53 Moderate self-attested SSP, POA&M, and the current FedRAMP posture letter. We operate a FedRAMP-aligned control baseline today and pursue formal authorization with our first agency sponsor. The target procurement-to-go-live window is 30–60 days depending on agency ATO timeline.
Contact sales@fedgrade.com (or the rename successor) with agency name, target seat count, and ATO timeline to open the conversation.
Last updated 2026-06-12.