Sovereign US-only environment or on-premises. Smart-card. STIG-hardened. IPv6-native.
Federal agencies, DoD components, and defense industrial base contractors operate inside the strictest compliance perimeter on Earth. Tessarac's Federal plan ships STIG-hardened images, FIPS 140-3 validated cryptography enforced, smart-card (CAC/PIV) sign-in, and IPv6-native control + data planes for OMB M-21-07 alignment.

Regulatory posture
The frameworks federal customers are audited against.
The federal stack is FedRAMP (Low / Moderate / High), DoD IL2-IL6 for cloud workloads, CMMC 2.0 (L1-L3) for the defense industrial base, ITAR for export-controlled material, CJIS for criminal-justice data, IRS Pub 1075 for federal tax information. Tessarac's Federal plan covers the High / IL5 / L3 envelope and inherits everything below it.
- FedRAMP High — Phase 3 3PAO assessment underway; pursuing Agency Authorization with a sponsoring agency
- DoD IL5 — Phase 4 sovereign SaaS launch readiness drafted; inherits FedRAMP High baseline
- CMMC 2.0 L2 / L3 — control mapping published in the Tessarac compliance repo
- ITAR — sovereign deployment patterns; export-controlled material never leaves the customer's compliance boundary
- CJIS + IRS Pub 1075 — sovereign deployment patterns documented; reach out for the runbook
- OMB M-21-07 — IPv6-native control plane and data plane; AAAA records published; cordon rules emit dual-stack
The federal-shaped deployment
STIG-hardened images, FIPS-validated cryptography enforced, smart-card sign-in for every operator account, and a deployment shape that lands in our sovereign US-only environment or fully on-premises.

Smart-card (CAC/PIV) sign-in
Embedded DoD/FCPCA trust bundle, OCSP + CRL revocation checking, PIN-protected reader integration. Required by default on the Federal plan; available on every paid plan. Operator-only (workforce) plus end-user options.

STIG-hardened images, FIPS-validated crypto
Federal plan ships STIG-hardened base images audited against the latest DISA STIG. FIPS 140-3 validated cryptography enforced across every component — no opt-out, no operator misconfiguration window.

Sovereign US-only environment or fully on-premises
Deploy to our sovereign US-only environment on FedRAMP-authorized infrastructure, OR run fully on-premises in your air-gapped environment with no outbound connectivity required. Same product, both deployment shapes.

Tamper-evident audit + log shipping
Hash-chained audit log; export to your existing SIEM, your own object-storage bucket inside the sovereign boundary, syslog, or a Linux host. Customer opt-out of Tessarac retention entirely — sovereign deployments keep nothing outside the boundary.
Why a sovereign-deployable platform matters
The vendor risk model is different inside the boundary.
In commercial SaaS, you trust your vendor. In federal SaaS, you assume your vendor will be subpoenaed, attacked, and audited — sometimes all in the same week. Tessarac is built so the customer holds the keys, the customer can opt out of vendor retention, and the customer can run the same product fully offline if the operational risk math says so.
- Per-tenant ECDSA P-384 trust anchor with HSM / cloud-KMS / BYOK options — operator key path is independent of Tessarac
- Customer opt-out of Tessarac retention entirely — sovereign deployments keep nothing outside the boundary
- Air-gapped install — no outbound connectivity required during install or operation; offline bundle ships with the Federal plan
- Out-of-band cordon — even if the agent is compromised, isolation works via the cloud control plane
- Compliance evidence collected continuously — audit-day fire drills end
Talk to a Tessarac federal architect
Federal plan starts at $500k/yr. Pricing scales with team-members + protected-systems, not with audit-team headcount.