ComplianceComing soon · Security Platform

Auditable today. Sovereign-deployable. Exportable.

FedRAMP High, DoD IL5, CMMC L3, ITAR, CJIS, IRS Pub 1075, SOC 2 Type 2, HIPAA, PCI-DSS v4. Tessarac ships with the controls, the hardened images, the audit log, and the documentation packet — not just a checklist on a marketing page.

Continuous audit chain with interlocking emerald hexagonal blocks and compliance framework emblems.

Federal compliance posture (M-21-07 + IPv6 mandate)

IPv6-native control plane and data plane.

OMB M-21-07 directs federal agencies to operate IPv6-only by default. Tessarac satisfies the FedRAMP IPv6 capability requirement out of the box: every endpoint (control plane, telemetry, install CDN, OIDC discovery, JWKS) listens on dual-stack, every cordon rule emits both IPv4 and IPv6 ACL entries, every NetworkPolicy generated by the operator includes IPv6 ipBlock entries alongside IPv4.

  • Dual-stack [::]:port HTTP listeners on every gateway and per-target internal RPC port
  • AAAA records published alongside A records for tessarac.com and every subdomain in our DNS automation
  • Cordon rules emit both nftables / WFP / PF v4 and v6 chains — no half-blind isolation
  • CSPM rule registry flags IPv6-disabled VPCs as a recommendation against the M-21-07 baseline
  • K8s NetworkPolicies generated by the Tessarac operator include both IPv4 and IPv6 ipBlock entries
  • Cloud workload identity enrollment validates source addresses on both stacks — no silent IPv4 fallback

Every control mapped, every framework documented

The Tessarac compliance repo carries the full mapping table. Pick a framework, find the control, see which Tessarac component implements it and where the evidence lives.

  • Cross-cloud security posture overview with multi-provider correlation.

    FedRAMP High + IL5

    Phase 3 3PAO assessment underway. Federal plan deploys to a sovereign US-only environment on STIG-hardened images with FIPS 140-3 validated cryptography enforced. IL5 readiness drafted for the Phase 4 sovereign SaaS launch.

  • Append-only audit trail with hash-chained block visualization.

    SOC 2 Type 2 + HIPAA + PCI-DSS

    Going straight to Type 2 (no Type 1 step) — observation period open in Phase 1. HIPAA Business Associate Agreement available on the Paid plan. PCI-DSS v4 reference architecture published.

  • Concentric cordon rings showing graduated isolation tiers.

    Tamper-evident audit log

    Every event is hash-chained. Verify the chain from any starting block to any ending block; tampering surfaces as a hash mismatch. Logs export to any object store, syslog, or any Linux host.

  • Role-based access control surface with policy gates.

    Customer opt-out of vendor retention

    Customers may opt out of Tessarac retaining their audit logs entirely. We keep only what we need for our own business compliance. Self-hosted plans always win this one — Tessarac wins it on cloud too.

The compliance preset model

Pick a baseline. Tessarac applies it.

Compliance presets are platform-wide, system-seeded baselines (NIST 800-63 AAL2/AAL3, FedRAMP Low/Moderate/High, PCI-DSS v4, HIPAA, SOC 2, CIS Controls v8 IG1/IG2/IG3). Apply-preset copies the preset's baseline_json into a new tenant policy version; subsequent operator tightenings layer on top.

  • A lower-level scope can only TIGHTEN a higher-level setting — never loosen. Loosening the baseline requires a two-admin attestation and lands in the audit log
  • Per-tenant compliance preset auto-routes telemetry, log shipping, and LLM analysis to the appropriate region (sovereign US-only AI inference for federal tenants, accredited regional AI gateways elsewhere)
  • Continuous evidence collection mapped to every framework — no audit-day fire drill
  • Sub-processor list published in the trust portal, updated 30 days before any change

Compliance built into the platform, not bolted on

Pick the framework, deploy the variant, ship the evidence. The Tessarac compliance repo has the full control mapping.