Federal & DefenseComing soon · Security Platform

Sovereign US-only environment or on-premises. Smart-card. STIG-hardened. IPv6-native.

Federal agencies, DoD components, and defense industrial base contractors operate inside the strictest compliance perimeter on Earth. Tessarac's Federal plan ships STIG-hardened images, FIPS 140-3 validated cryptography enforced, smart-card (CAC/PIV) sign-in, and IPv6-native control + data planes for OMB M-21-07 alignment.

Privileged access broker with session-replay terminal frames in deep midnight blue.

Regulatory posture

The frameworks federal customers are audited against.

The federal stack is FedRAMP (Low / Moderate / High), DoD IL2-IL6 for cloud workloads, CMMC 2.0 (L1-L3) for the defense industrial base, ITAR for export-controlled material, CJIS for criminal-justice data, IRS Pub 1075 for federal tax information. Tessarac's Federal plan covers the High / IL5 / L3 envelope and inherits everything below it.

  • FedRAMP High — Phase 3 3PAO assessment underway; pursuing Agency Authorization with a sponsoring agency
  • DoD IL5 — Phase 4 sovereign SaaS launch readiness drafted; inherits FedRAMP High baseline
  • CMMC 2.0 L2 / L3 — control mapping published in the Tessarac compliance repo
  • ITAR — sovereign deployment patterns; export-controlled material never leaves the customer's compliance boundary
  • CJIS + IRS Pub 1075 — sovereign deployment patterns documented; reach out for the runbook
  • OMB M-21-07 — IPv6-native control plane and data plane; AAAA records published; cordon rules emit dual-stack

The federal-shaped deployment

STIG-hardened images, FIPS-validated cryptography enforced, smart-card sign-in for every operator account, and a deployment shape that lands in our sovereign US-only environment or fully on-premises.

  • Multi-factor authentication challenge surface.

    Smart-card (CAC/PIV) sign-in

    Embedded DoD/FCPCA trust bundle, OCSP + CRL revocation checking, PIN-protected reader integration. Required by default on the Federal plan; available on every paid plan. Operator-only (workforce) plus end-user options.

  • Cross-cloud security posture overview with multi-provider correlation.

    STIG-hardened images, FIPS-validated crypto

    Federal plan ships STIG-hardened base images audited against the latest DISA STIG. FIPS 140-3 validated cryptography enforced across every component — no opt-out, no operator misconfiguration window.

  • Concentric cordon rings showing graduated isolation tiers.

    Sovereign US-only environment or fully on-premises

    Deploy to our sovereign US-only environment on FedRAMP-authorized infrastructure, OR run fully on-premises in your air-gapped environment with no outbound connectivity required. Same product, both deployment shapes.

  • Append-only audit trail with hash-chained block visualization.

    Tamper-evident audit + log shipping

    Hash-chained audit log; export to your existing SIEM, your own object-storage bucket inside the sovereign boundary, syslog, or a Linux host. Customer opt-out of Tessarac retention entirely — sovereign deployments keep nothing outside the boundary.

Why a sovereign-deployable platform matters

The vendor risk model is different inside the boundary.

In commercial SaaS, you trust your vendor. In federal SaaS, you assume your vendor will be subpoenaed, attacked, and audited — sometimes all in the same week. Tessarac is built so the customer holds the keys, the customer can opt out of vendor retention, and the customer can run the same product fully offline if the operational risk math says so.

  • Per-tenant ECDSA P-384 trust anchor with HSM / cloud-KMS / BYOK options — operator key path is independent of Tessarac
  • Customer opt-out of Tessarac retention entirely — sovereign deployments keep nothing outside the boundary
  • Air-gapped install — no outbound connectivity required during install or operation; offline bundle ships with the Federal plan
  • Out-of-band cordon — even if the agent is compromised, isolation works via the cloud control plane
  • Compliance evidence collected continuously — audit-day fire drills end

Talk to a Tessarac federal architect

Federal plan starts at $500k/yr. Pricing scales with team-members + protected-systems, not with audit-team headcount.