Auditable today. Sovereign-deployable. Exportable.
FedRAMP High, DoD IL5, CMMC L3, ITAR, CJIS, IRS Pub 1075, SOC 2 Type 2, HIPAA, PCI-DSS v4. Tessarac ships with the controls, the hardened images, the audit log, and the documentation packet — not just a checklist on a marketing page.

Federal compliance posture (M-21-07 + IPv6 mandate)
IPv6-native control plane and data plane.
OMB M-21-07 directs federal agencies to operate IPv6-only by default. Tessarac satisfies the FedRAMP IPv6 capability requirement out of the box: every endpoint (control plane, telemetry, install CDN, OIDC discovery, JWKS) listens on dual-stack, every cordon rule emits both IPv4 and IPv6 ACL entries, every NetworkPolicy generated by the operator includes IPv6 ipBlock entries alongside IPv4.
- Dual-stack [::]:port HTTP listeners on every gateway and per-target internal RPC port
- AAAA records published alongside A records for tessarac.com and every subdomain in our DNS automation
- Cordon rules emit both nftables / WFP / PF v4 and v6 chains — no half-blind isolation
- CSPM rule registry flags IPv6-disabled VPCs as a recommendation against the M-21-07 baseline
- K8s NetworkPolicies generated by the Tessarac operator include both IPv4 and IPv6 ipBlock entries
- Cloud workload identity enrollment validates source addresses on both stacks — no silent IPv4 fallback
Every control mapped, every framework documented
The Tessarac compliance repo carries the full mapping table. Pick a framework, find the control, see which Tessarac component implements it and where the evidence lives.

FedRAMP High + IL5
Phase 3 3PAO assessment underway. Federal plan deploys to a sovereign US-only environment on STIG-hardened images with FIPS 140-3 validated cryptography enforced. IL5 readiness drafted for the Phase 4 sovereign SaaS launch.

SOC 2 Type 2 + HIPAA + PCI-DSS
Going straight to Type 2 (no Type 1 step) — observation period open in Phase 1. HIPAA Business Associate Agreement available on the Paid plan. PCI-DSS v4 reference architecture published.

Tamper-evident audit log
Every event is hash-chained. Verify the chain from any starting block to any ending block; tampering surfaces as a hash mismatch. Logs export to any object store, syslog, or any Linux host.

Customer opt-out of vendor retention
Customers may opt out of Tessarac retaining their audit logs entirely. We keep only what we need for our own business compliance. Self-hosted plans always win this one — Tessarac wins it on cloud too.
The compliance preset model
Pick a baseline. Tessarac applies it.
Compliance presets are platform-wide, system-seeded baselines (NIST 800-63 AAL2/AAL3, FedRAMP Low/Moderate/High, PCI-DSS v4, HIPAA, SOC 2, CIS Controls v8 IG1/IG2/IG3). Apply-preset copies the preset's baseline_json into a new tenant policy version; subsequent operator tightenings layer on top.
- A lower-level scope can only TIGHTEN a higher-level setting — never loosen. Loosening the baseline requires a two-admin attestation and lands in the audit log
- Per-tenant compliance preset auto-routes telemetry, log shipping, and LLM analysis to the appropriate region (sovereign US-only AI inference for federal tenants, accredited regional AI gateways elsewhere)
- Continuous evidence collection mapped to every framework — no audit-day fire drill
- Sub-processor list published in the trust portal, updated 30 days before any change
Compliance built into the platform, not bolted on
Pick the framework, deploy the variant, ship the evidence. The Tessarac compliance repo has the full control mapping.