Skip to content

Federal Deployment Overview

GOVERN Federal is the hardened deployment configuration of the GOVERN AI Governance Platform designed for U.S. federal agencies, DoD components, and defense contractors operating under federal AI governance requirements.

Regulatory Context

Federal AI deployments are subject to a layered compliance framework:

RequirementAuthorityScope
EO 14110White HouseAI safety and security standards for federal use
OMB M-24-10OMBAI governance requirements for federal agencies
NIST AI RMFNISTAI risk management framework
FedRAMPGSA/OMBCloud security authorization
CMMC 2.0DoDDefense contractor cybersecurity
NIST SP 800-53NISTSecurity controls for federal information systems
IL2–IL6DoDImpact Level controls for defense workloads

GOVERN Federal Architecture

GOVERN Federal is a configuration of GOVERN Container (values-federal.yaml) with:

  • GovCloud deployment — AWS GovCloud (US-Gov-East/West) or Azure Government
  • FedRAMP-authorized components — Only FedRAMP-authorized third-party services
  • FIPS 140-2 encryption — All data in transit and at rest
  • CAC/PIV authentication — No username/password authentication
  • IL2/IL4/IL6 configurations — Separate values files per impact level
  • Air-gap capability — Full offline bundle for classified networks
  • OSCAL export — Machine-readable compliance data in NIST OSCAL format
  • Continuous ATO — Automated control monitoring for cATO programs

Deployment Paths

PathUse CaseTime to Deploy
GovCloud (AWS)Unclassified + CUI workloads2–4 hours
GovCloud (Azure)M365/Entra-integrated environments2–4 hours
Air-gappedClassified networks (IL5/IL6)1–3 days
DISA IL2DoD public-facing workloads4–8 hours
DISA IL4Controlled Unclassified Information4–8 hours
DISA IL6Secret classification1–2 weeks

Getting Started

  1. GovCloud Deployment — Deploy to AWS or Azure GovCloud
  2. Air-Gapped Installation — Offline bundle for classified networks
  3. Impact Level Configuration — IL2, IL4, IL5, IL6 settings
  4. FedRAMP Authorization — Authorization path and documentation
  5. CMMC Compliance — Level 2 and Level 3 compliance mapping
  6. NIST 800-53 Controls — Control implementation statements
  7. CAC/PIV Authentication — Smart card authentication setup
  8. OSCAL Export — Machine-readable compliance output